Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.2CPE matchmatch criteria | cpe:2.3:a:apache:fesod:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component
Jun 1, 2026CVE-2026-49328: Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF
Jun 1, 2026