Executive brief
Koha, an open-source integrated library system, contains a vulnerability in its Z39.50 configuration module. An attacker can exploit this to perform Server-Side Request Forgery (SSRF), allowing them to scan internal network services or interact with internal systems that are not normally accessible from the internet. This could lead to further internal network compromise or unauthorized data access.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Koha versions up to and including 25.11. The flaw is located in the Z39.50/SRU server configuration module, where the application fails to properly validate or restrict the host and port parameters provided by a user. By configuring a malicious Z39.50 server entry and initiating a search via 'z3950_search.pl', an attacker can force the Koha server to make outbound requests to arbitrary internal or external IP addresses and ports. While the initial NVD description mentions remote code execution, the researcher's technical write-up specifically demonstrates SSRF used for internal port scanning. Authentication is likely required to access the administration dashboard to configure the server settings.
Affected products
- Koha Community Koha <= 25.11
Timeline
- 2025-12-31: disclosed: Researcher published technical details of SSRF vulnerability
- 2026-06-03: advisory: CVE-2026-26379 published by NVD/MITRE