CVE-2026-39087

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-23 16:16

Updated : 2026-07-04 16:17


NVD link : CVE-2026-39087

Mitre link : CVE-2026-39087

CVE.ORG link : CVE-2026-39087


JSON object : View

Products Affected

No product.

CWE
CWE-777

Regular Expression without Anchors

CWE-94

Improper Control of Generation of Code ('Code Injection')