CVE-2026-72597: Friendica

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an internal IP deny list. An attacker can use this to scan the internal network or access cloud metadata services.

Affected products

  • Friendica Friendica: up to and including 2026.08-dev

Published 2026-08-11. Last modified 2026-08-28.