CVE-2026-39087 Details
Description
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
A vulnerability allowing remote code execution has been identified in ntfy versions prior to 2.21. The issue arises in the parseActions function, where an unanchored regular expression is used to validate web push endpoint URLs. This flaw enables attackers to craft URLs that bypass the allow-list and direct requests to arbitrary internal or external destinations.
Users can upgrade to ntfy version 2.22.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-777 | Regular Expression without Anchors | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 4, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | [email protected] |