Junglewise Threat Intelligence

CVE-2026-33534: EspoCRM SSRF via internal-host validation bypass in Attachment API

CVE-2026-33534 · Severity: medium · CVSS 4.3 · Published 2026-04-13

Technologies: Espocrm. Vendors: Espocrm.

Executive brief

EspoCRM, an open-source Customer Relationship Management (CRM) platform, contains a security flaw that allows logged-in users to bypass internal network protections. By providing specially formatted web addresses, an attacker can force the CRM server to connect to internal services that are normally hidden from the internet. This could lead to the exposure of sensitive internal data or allow the attacker to interact with other private systems within the organization's network.

Technical details

An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in EspoCRM's HostCheck::isNotInternalHost() function. The component relies on PHP's filter_var with FILTER_VALIDATE_IP, which fails to recognize alternative IPv4 representations like octal notation (e.g., 0177.0.0.1). When such a notation is used, the validation logic falls through to a DNS lookup that returns no records, incorrectly flagging the host as safe. Subsequently, cURL normalizes the address and executes the request to the internal or loopback destination. Attackers can exploit this via the /api/v1/Attachment/fromImageUrl endpoint to reach internal services and save the responses as attachments. The issue is resolved in version 9.3.4.

Affected products

  • EspoCRM EspoCRM <= 9.3.3

Timeline

  • 2026-03-24: patched: Version 9.3.4 released
  • 2026-04-13: disclosed: Security advisory published
  • 2026-04-13: advisory: CVE-2026-33534 assigned

References

Related threats