CVE-2026-33182 affects the Saloon PHP library prior to version 4.0.0, enabling Server-Side Request Forgery (SSRF) and credential leakage. This vulnerability allows an attacker-controlled absolute URL in a request endpoint to override the connector's base URL, redirecting requests and sensitive authentication data to arbitrary third-party hosts. Rated with a CVSS score of 7.5 HIGH, it presents a critical risk with a network attack vector, low attack complexity, and high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:saloon:saloon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.