CVE-2026-27600 Details
Description
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although the application does not return the response body from the target service, its UI behavior differs depending on the network state of the destination. This creates a behavioral side-channel that enables internal service enumeration. This vulnerability is fixed in 0.24.0-rc.1.
A blind server-side request forgery (SSRF) vulnerability has been identified in HomeBox versions prior to 0.24.0-rc.1. This vulnerability allows authenticated users to send HTTP POST requests to arbitrary URLs without any validation or restrictions on the host, IP address, or port. Although the application does not disclose the response body from the target service, the user interface behavior varies based on the network state of the destination. This discrepancy creates a behavioral side-channel that can be exploited for internal service enumeration.
Users are advised to update HomeBox to version 0.24.0-rc.1 or later. After updating, consult the HomeBox documentation on security considerations for notifiers to apply the appropriate security settings. By default, only reserved IPs and Cloud metadata endpoints are blocked. To restrict access to local networks or localhost, additional configuration is required.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-cm7p-5mg5-82pm | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sysadminsmedia homebox | <= 0.23.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | New CVE Received | [email protected] |