CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVE ID :CVE-2026-40168
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endp...
Related Vulnerabilities
- CVE-2026-35665: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook han MEDIUM
- CVE-2026-5724: The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor N/A
- CVE-2026-34727: Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path HIGH
- CVE-2026-35666: OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fa HIGH
- CVE-2026-35647: OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass MEDIUM
Related Coverage
Threat Actors