Junglewise Threat Intelligence

CVE-2026-64873: Regular Labs Cache Cleaner Pro SSRF via custom query URLs

CVE-2026-64873 · Severity: info · CVSS 0 · Published 2026-07-23

Technologies: Regular Labs Cache Cleaner Pro. Vendors: Regular Labs.

Executive brief

The Cache Cleaner Pro extension for Joomla, which helps administrators manage and clear website cache, contains a security flaw. This vulnerability allows an attacker to use the extension to send requests to internal network services that are normally protected from the public internet. This could lead to the exposure of sensitive internal data or unauthorized access to private infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Regular Labs Cache Cleaner Pro extension for Joomla (versions 1.0.0 through 9.7.6). The flaw is located in the handling of custom query URLs, which do not sufficiently validate user-supplied input. An attacker can exploit this by providing a malicious URL that forces the server to make requests to internal or reserved network services. This can be used to bypass firewalls, scan internal networks, or access metadata services in cloud environments. The vulnerability is tracked as CWE-918.

Affected products

  • Regular Labs Cache Cleaner Pro extension for Joomla 1.0.0-9.7.6

Timeline

  • 2026-07-23: disclosed: CVE-2026-64873 published by the Joomla! Project

References

Related threats