CVE-2026-26379: Koha
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.
Affected products
- Koha Koha: up to and including 25.11.00
Published 2026-06-03. Last modified 2026-07-22.