GHSL-2026-045: Server-Side Request Forgery (SSRF) in Wekan - CVE-2026-30844
Published Mar 6, 2026
·Updated
Wekan v8.32 is vulnerable to a Server-Side Request Forgery (SSRF) flaw (tracked as GHSL-2026-045) that arises from improper handling of attachment URL loading, potentially allowing attackers to manipulate server requests and access internal systems or sensitive data.
Affected Software
1 affected component
Wekan Wekan=8.32
Event History
Mar 6, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2026-045?
The severity of GHSL-2026-045 is rated at 58, indicating a moderate risk level.
2
How do I fix GHSL-2026-045?
To fix GHSL-2026-045, upgrade Wekan to version 8.34 or later where the vulnerability has been addressed.
3
What systems are affected by GHSL-2026-045?
GHSL-2026-045 affects Wekan version 8.32 due to its improper handling of attachment URL loading.
4
What type of vulnerability is GHSL-2026-045?
GHSL-2026-045 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
What can attackers potentially access through GHSL-2026-045?
Attackers can potentially manipulate server requests and access internal systems or sensitive data due to GHSL-2026-045.