Junglewise Threat Intelligence

CVE-2026-48013: Shopware SSRF in Media External-Link endpoint

CVE-2026-48013 · Severity: medium · CVSS 4.1 · Published 2026-07-23

Technologies: shopware/core (Packagist), shopware/platform (Packagist), Shopware. Vendors: Packagist, Shopware.

Executive brief

Shopware, an open-source e-commerce platform, contains a security flaw in how it handles external links within its media management system. An authorized administrator could exploit this to force the server to send requests to internal network addresses or cloud metadata services that are normally hidden from the internet. This could allow an attacker to perform internal network reconnaissance or leak sensitive information about the server's hosting environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Shopware MediaUploadService due to inconsistent URL validation between different upload flows. The `/api/_action/media/external-link` endpoint uses the `linkURL()` method, which only performs a basic regex check for the protocol prefix instead of validating the destination IP against private or reserved ranges. An authenticated attacker with administrative privileges can trigger HTTP HEAD requests to internal IP addresses (e.g., 10.x.x.x, 127.0.0.1) or cloud metadata endpoints (169.254.169.254). This allows for internal port scanning and information disclosure via the `content-length` header, which is stored in the database as the file size. The vulnerability is mitigated by the requirement for high privileges (Admin) and is patched in versions 6.6.10.18 and 6.7.10.1.

Affected products

  • Shopware Shopware < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1
  • Shopware Platform < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1

Timeline

  • 2026-05-19: patched: Security releases 6.6.10.18 and 6.7.10.1 published
  • 2026-05-19: advisory: GitHub Security Advisory GHSA-gq96-5pfx-f4vc published
  • 2026-07-23: disclosed: CVE-2026-48013 published to NVD

References

Related threats