Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linkace
Linkace linkace |
|
| CPEs | cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linkace
Linkace linkace |
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovah
Kovah linkace |
|
| Vendors & Products |
Kovah
Kovah linkace |
Tue, 10 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the provided URL (LinkRepository::create() calls HtmlMeta::getFromUrl()). The LinkStoreRequest validation rules do not include NoPrivateIpRule, allowing server-side requests to internal network addresses, Docker service hostnames, and cloud metadata endpoints. The project already has a NoPrivateIpRule class (app/Rules/NoPrivateIpRule.php) but it is only applied in FetchController.php (line 99), not in the primary link creation path. | |
| Title | LinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequest | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-11T14:37:18.597Z
Reserved: 2026-03-07T17:34:39.980Z
Link: CVE-2026-30953
Updated: 2026-03-11T14:37:11.629Z
Status : Analyzed
Published: 2026-03-10T21:16:48.347
Modified: 2026-03-17T16:13:30.093
Link: CVE-2026-30953
No data.
OpenCVE Enrichment
Updated: 2026-03-20T14:33:57Z