CVE-2026-18736: Shlinkio Shlink
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.
Affected products
- Shlinkio Shlink
Published 2026-08-03. Last modified 2026-09-09.