Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Homarr
Homarr homarr |
|
| CPEs | cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Homarr
Homarr homarr |
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Homarr-labs
Homarr-labs homarr |
|
| Vendors & Products |
Homarr-labs
Homarr-labs homarr |
Sat, 07 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote attacker to force the Homarr server to perform arbitrary outbound HTTP requests. This can be used as an internal network access primitive (e.g., reaching loopback/private ranges) from the Homarr host/container network context. This issue has been patched in version 1.54.0. | |
| Title | Homarr: Unauthenticated SSRF in rssFeed.ts | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:44:25.842Z
Reserved: 2026-02-24T02:31:33.266Z
Link: CVE-2026-27797
Updated: 2026-03-09T20:41:59.275Z
Status : Analyzed
Published: 2026-03-07T06:16:09.843
Modified: 2026-03-10T16:24:46.050
Link: CVE-2026-27797
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:00:10Z