CVE-2026-101005: October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
October CMSto a version that resolves this vulnerability.Fixed in 4.3.5
Event History
Frequently Asked Questions
Which deployments are affected?
October CMS versions up to 4.3.4 are affected. Version 4.3.5 is identified as mitigating the issue.
Does exploitation require authentication or user interaction?
No. The supplied severity vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
Is a public exploit available?
Yes. The vulnerability data states that an exploit is public and may be used.
What should teams do to remediate the issue?
Upgrade the affected October CMS component to version 4.3.5.