CVE-2026-33401 is a Server-Side Request Forgery (SSRF) vulnerability affecting Wallos, an open-source personal subscription tracker, in versions prior to 4.7.0. An authenticated attacker can exploit this flaw by supplying crafted URLs to specific endpoints, enabling access to internal network services, cloud metadata, or localhost-bound services. Rated Medium severity with a CVSS score of 6.5, the primary impact is high confidentiality due to potential information disclosure. This vulnerability requires low privileges and has low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7.0CPE matchmatch criteria | cpe:2.3:a:wallosapp:wallos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.