← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 20:46via CVE Program

cve-2026-54494

Brief

Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4

Read more on CVE Program