Junglewise Threat Intelligence

CVE-2026-40168: Gitroom Postiz SSRF via redirect bypass in stream endpoint

CVE-2026-40168 · Severity: high · CVSS 8.2 · Published 2026-04-10

Technologies: Gitroom Postiz. Vendors: Gitroom.

Executive brief

Postiz, an AI-powered social media scheduling tool, contains a security flaw that allows attackers to trick the server into making unauthorized requests to internal systems. While the software attempts to block access to private networks, it fails to check the final destination if a web request is redirected. This could allow an attacker to scan internal corporate networks, interact with private databases or services, and potentially access sensitive cloud configuration data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `/api/public/stream` endpoint of Postiz due to insufficient validation of HTTP redirects. While the application performs an initial check to block internal or private IP addresses, it does not perform subsequent validation if the initial public URL redirects the request. An unauthenticated attacker can exploit this by providing a URL they control that redirects to internal resources, such as cloud metadata services (169.254.169.254) or internal APIs. This can lead to internal network scanning, interaction with unauthenticated internal services, and potential exposure of cloud credentials. The vulnerability is patched in version 2.21.5.

Affected products

  • Gitroom Postiz < 2.21.5

Timeline

  • 2026-04-03: disclosed: Postiz received the initial report.
  • 2026-04-09: patched: Version 2.21.5 released.
  • 2026-04-10: advisory: CVE-2026-40168 published.

References

Related threats