CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVE ID :CVE-2026-40168
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endp...
Related Vulnerabilities
- CVE-2025-62718: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF MEDIUM
- CVE-2026-40086: Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the MEDIUM
- CVE-2026-35655: OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution t MEDIUM
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
- CVE-2026-6013: A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSet HIGH
Related Coverage
Threat Actors