CVE-2026-71280: Go-Shiori Shiori
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).
Affected products
- Go-Shiori Shiori: any version
Published 2026-08-05. Last modified 2026-08-26.