CVE-2023-30019: Evilmartians Imgproxy

Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.

imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

Affected products

Published 2023-05-08. Last modified 2026-06-17.