CVE-2026-96652: Plex Media Server
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.
Affected products
- Plex Media Server: before 1.43.0.10861 (fixed in 1.43.0.10861)
Published 2026-09-23. Last modified 2026-09-29.