Junglewise Threat Intelligence

CVE-2026-45660: Statamic CMS SSRF in Glide image proxy

CVE-2026-45660 · Severity: medium · CVSS 5.4 · Published 2026-05-29

Technologies: Statamic. Vendors: Statamic.

Executive brief

Statamic is a content management system used to build and manage websites. A security flaw in its image processing component allows unauthorized users to trick the server into making requests to internal systems. This could lead to the exposure of sensitive internal data, such as cloud metadata or private network information, which is normally hidden from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Statamic's Glide image proxy due to insufficient normalization of IP addresses before performing public-IP validation. An unauthenticated attacker can bypass these checks by using alternative IP representations to force the server to make HTTP requests to internal addresses, including loopback (127.0.0.1), private network ranges, and cloud metadata endpoints. The vulnerability specifically affects sites that pass user-supplied URLs to Glide and are running on PHP versions older than 8.3. The issue is resolved in Statamic versions 5.73.22 and 6.18.1.

Affected products

  • Statamic Statamic CMS < 5.73.22, < 6.18.1

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats