CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVE ID :CVE-2026-40168
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endp...
Related Vulnerabilities
- CVE-2026-5724: The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor N/A
- CVE-2026-35663: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators HIGH
- CVE-2026-5983: A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDD HIGH
- CVE-2026-33551: An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0. LOW
- CVE-2026-40073: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass HIGH
Related Coverage
Threat Actors