CVE-2026-33407

Severity CVSS v4.0:
HIGH
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
24/03/2026
Last modified:
26/03/2026

Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search terms, which can be controlled by attackers to trigger outbound requests to arbitrary domains. This issue has been patched in version 4.7.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wallosapp:wallos:*:*:*:*:*:*:*:* 4.7.0 (excluding)