CVE-2026-26379

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
03/06/2026
Last modified:
22/07/2026

Description

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* 25.11.00 (including)