CVE-2026-33953

Published
View on NVD ↗
CVSS v3
8.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.

LinkAce is a self-hosted archive to collect links of your favorite websites.
GitHubGitHub
3.29K