CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVE ID :CVE-2026-40168
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endp...
Related Vulnerabilities
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
- CVE-2026-39922: GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnera N/A
- CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow MEDIUM
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
- CVE-2026-5217: The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin f HIGH
Related Coverage
Threat Actors