CVE-2026-71280: Go-Shiori Shiori

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).

Affected products

Published 2026-08-05. Last modified 2026-08-26.