CVE-2026-100909 Details
Description
A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.
A server-side request forgery (SSRF) vulnerability has been identified in OctoberCMS versions prior to 4.1.19, 4.2.25, and 4.3.4. The issue arises in the image resizing functionality, specifically within the 'getSourcePathForResize' method of 'modules/system/classes/ResizeImages.php'. The vulnerability allows manipulation of the 'realSourcePath' argument, bypassing existing SSRF protections and potentially leading to unauthorized access of internal services or files.
Users can upgrade to OctoberCMS versions 4.3.5 or 4.4.0 to address this vulnerability. For those unable to upgrade immediately, it is recommended to audit template code and backend widget configurations for uses of the '|'resize' filter or direct 'ResizeImages::resize()' calls that accept untrusted string input, and to validate the scheme is 'http' or 'https' before passing it in.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xGenesi/CVE/blob/main/October_CMS_Stream_Wrapper_Injection.md | [email protected] | ExploitTechnical Analysis |
| https://github.com/octobercms/october/commit/0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58 | [email protected] | Source CodeVendor |
| https://github.com/octobercms/october/releases/tag/v4.3.5 | [email protected] | Release NotesVendor |
| https://github.com/octobercms/october/security/advisories/GHSA-2xmm-m4wv-3fjh | [email protected] | AdvisoryRemedyVendor |
| https://vuldb.com/cve/CVE-2026-100909 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919993 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410869 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410869/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OctoberCMS | <= 4.3.4 (semver) <= 4.2.25 (semver) <= 4.1.19 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion