CVE-2026-61520 Details
Description
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services.
A server-side request forgery (SSRF) vulnerability has been identified in the image proxy of Simple Machines Forum (SMF) versions 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df. This vulnerability allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags. The proxy fetches these URLs without validating the resolved destination IPs against private address ranges, loopback, or link-local addresses. Exploitation of this vulnerability could lead to unauthorized access to internal services, such as cloud instance metadata endpoints, internal web applications, and container network services.
Users can update to Simple Machines Forum 2.1 versions after 4bf35cf or 3.0 versions after b4d23df to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Simple Machines Forum | >= 2.1.0, < 4bf35cf9e45573a5f55a6f52995086c1da89c096 >= 3.0.0, < b4d23dfd74a511587c605f9d294cefc3a75b4b26 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion