CVE-2026-47170 Details
Description
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning, service fingerprinting, and retrieval of internal HTTP responses which are stored in the publicly accessible media pool. This issue has been patched in version 1.1.
A server-side request forgery (SSRF) vulnerability has been identified in Garlic-Hub versions prior to 1.1. This vulnerability allows authenticated users to send arbitrary HTTP requests to internal services through the 'uploadFromUrl' endpoint. Exploitation of this issue could lead to internal port scanning, service fingerprinting, and the retrieval of internal HTTP responses, which are then stored in the publicly accessible media pool.
Users are advised to upgrade to Garlic-Hub version 1.1 or later. If an upgrade is not possible, the 'uploadFromUrl' endpoint should be disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2026CISA-ADP
Assessed Jun 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/garlic-signage/garlic-hub/commit/076b6d70a43d9641c35cbd8042353b473e3241f5 | [email protected] | Source CodeVendor |
| https://github.com/garlic-signage/garlic-hub/security/advisories/GHSA-x24v-76hr-989r | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Garlic-Hub | < 1.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |
Volerion