CVE-2026-71210: Mealie-Recipes Mealie

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently.

Affected products

Published 2026-08-05. Last modified 2026-08-26.