mediumCVSS 4.9Vulnerability

CVE-2026-54242

### Impact The Glide image proxy's URL validation could be bypassed using DNS rebinding. The remote hostname was validated as publicly routable, but resolved again when the image was actually fetched, so an attacker controlling the hostname's DNS could rebind it to an internal address after validation. This could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. ### Patches This has been fixed in 5.73.24 and 6.20.1.

Properties

severity
medium
summary
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
epss_score
0.00147
cvss_score
4.9
ghsa_published
2026-06-26T23:03:28Z
source_url
https://github.com/advisories/GHSA-v5c4-wcpj-x73m
ghsa_updated
2026-06-26T23:03:29Z
ghsa_id
GHSA-v5c4-wcpj-x73m
cve_id
CVE-2026-54242
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
is_ghsa_only
false
epss_percentile
0.0442

Related Entities (6)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Server-Side Request Forgery (SSRF)
[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/statamic/cms

AFFECTS (1)

[Software]composer/statamic/cms

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54242 (CVSS 4.9) — Ninja Signal Threat Intelligence | Ninja Signal