Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. statamic/cms
  4. ›
  5. CVE-2026-45660

CVE-2026-45660: Statamic CMS: Server-Side Request Forgery via Glide

May 18, 2026 (updated June 9, 2026)

The Glide image proxy’s URL validation could be bypassed using an IP representation that wasn’t normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints.

This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected.

References

  • github.com/advisories/GHSA-pf9c-ch8r-2958
  • github.com/statamic/cms/security/advisories/GHSA-pf9c-ch8r-2958
  • nvd.nist.gov/vuln/detail/CVE-2026-45660

Code Behaviors & Features

Detect and mitigate CVE-2026-45660 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.73.22, all versions starting from 6.0.0-alpha.1 before 6.18.1

Fixed versions

  • 5.73.22
  • 6.18.1

Solution

Upgrade to versions 5.73.22, 6.18.1 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

packagist/statamic/cms/CVE-2026-45660.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:12 +0000.