CVE-2026-34443: FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR ranges. The entire 10.0.0.0/8 and 172.16.0.0/12 private ranges are unprotected. This issue has been patched in version 1.8.211.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.211
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34443?
CVE-2026-34443 is classified with a high severity due to its potential to allow SSRF attacks.
How do I fix CVE-2026-34443?
To fix CVE-2026-34443, upgrade FreeScout to version 1.8.211 or later.
What type of vulnerability is CVE-2026-34443?
CVE-2026-34443 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability.
Which versions of FreeScout are affected by CVE-2026-34443?
FreeScout versions prior to 1.8.211 are affected by CVE-2026-34443.
Where does CVE-2026-34443 occur in the FreeScout application?
CVE-2026-34443 occurs in the checkIpByMask() function located in app/Misc/Helper.php.