CVE-2026-71210: Mealie-Recipes Mealie
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently.
Affected products
- Mealie-Recipes Mealie: version 0 only
Published 2026-08-05. Last modified 2026-08-26.