CVE-2026-39087: Ntfy

Medium severity, CVSS 6.4. EPSS: 0.5% chance of exploitation in the next 30 days.

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

Affected products

  • Ntfy Ntfy: before 2.22.0 (fixed in 2.22.0)

Published 2026-04-23. Last modified 2026-07-04.