Junglewise Threat Intelligence

CVE-2026-9304: Calcom cal.diy SSRF via HTTP Redirect in Logo API

CVE-2026-9304 · Severity: medium · CVSS 5 · Published 2026-05-23

Technologies: Calcom Cal.diy, Cal.Com. Vendors: Cal.com.

Executive brief

Cal.com cal.diy, an open-source scheduling platform, contains a security flaw in its Logo API. This vulnerability allows an authenticated user to trick the server into making requests to internal systems that should be private. An attacker could use this to access sensitive internal data, such as cloud metadata or internal administrative services, potentially leading to a breach of confidential information.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `validateUrlForSSRF` function within `apps/web/app/api/logo/route.ts`. While the application validates the initial URL to block restricted IP ranges (like loopback or private CIDRs), it uses the Node.js `fetch()` API for the final request without disabling automatic redirect following (e.g., `redirect: "manual"`). This creates a Time-of-Check to Time-of-Use (TOCTOU) condition where an attacker can provide a public URL that passes initial validation but then issues a 301/302 redirect to a restricted internal resource, such as AWS IMDS (169.254.169.254) or local services. Successful exploitation requires authentication and the ability to modify Team or Organization parameters.

Affected products

  • calcom cal.diy up to 4.9.4

Timeline

  • 2026-04-06: disclosed: Initial discovery and PoC creation by YLChen-007.
  • 2026-05-23: advisory: CVE-2026-9304 published.

References

Related threats