CVE-2026-25123: Homarr

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that URL. This allows an unauthenticated attacker to trigger outbound HTTP requests from the Homarr server, enabling SSRF behavior and a reliable port-scanning primitive (open vs closed ports can be inferred from statusCode vs fetch failed and timing). This vulnerability is fixed in 1.52.0.

Affected products

  • Homarr Homarr: before 1.52.0 (fixed in 1.52.0)

Published 2026-02-06. Last modified 2026-06-17.