CVE-2026-39087: Ntfy
Medium severity, CVSS 6.4. EPSS: 0.5% chance of exploitation in the next 30 days.
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
Affected products
- Ntfy Ntfy: before 2.22.0 (fixed in 2.22.0)
Published 2026-04-23. Last modified 2026-07-04.