CVE-2026-107273: Gophish
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.
Affected products
- Gophish Gophish: from 0.11.0, up to and including 0.12.1
Published 2026-10-07. Last modified 2026-10-07.