CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVE ID :CVE-2026-40168
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endp...
Related Vulnerabilities
- CVE-2026-35619: OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endp MEDIUM
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-35664: OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface t MEDIUM
- CVE-2026-35649: OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to MEDIUM
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
Related Coverage
Threat Actors