CVE-2026-4907 identifies a Server-Side Request Forgery (SSRF) vulnerability within the sitemap.fetch function of Page-Replica Page Replica, affecting versions up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. This medium-severity flaw (CVSS 6.3) allows remote attackers with low privileges to manipulate the 'url' argument, potentially leading to limited impacts on confidentiality, integrity, and availability. A public exploit is available, and the vendor has not responded to disclosure attempts. While there is no indication of active exploitation or inclusion in the KEV catalog, the presence of a public exploit suggests a heightened risk. Due to a rolling release strategy, specific affected or patched version details are unavailable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Page-Replica | Page Replica | e4a7f52e75093ee318b4d5a9a9db6751050d2ad0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.