CVE-2026-100909
Received Received - Intake

OctoberCMS Server-Side Request Forgery in ResizeImages

Vulnerability report for CVE-2026-100909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
october cms to 4.1.20 (exc)
october cms to 4.2.26 (exc)
october cms to 4.3.5 (exc)
october cms 4.3.5
october cms 4.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100909 is a server-side request forgery (SSRF) vulnerability in OctoberCMS affecting versions up to 4.1.19, 4.2.25, and 4.3.4. It exists in the ResizeImages.php file where the getSourcePathForResize function improperly validates input paths. Attackers can exploit this by manipulating the realSourcePath argument to bypass protections and trigger SSRF or PHAR deserialization, leading to remote code execution.

Detection Guidance

To detect this vulnerability, inspect October CMS installations for versions up to 4.3.4. Check for the presence of the ResizeImages class in modules/system/classes/ResizeImages.php and verify if the getSourcePathForResize function uses incomplete scheme validation like strpos($realSourcePath, 'http') === 0. Look for PHAR-PNG polyglot files or unusual image paths in the cache or resized image storage.

Impact Analysis

This vulnerability allows unauthenticated attackers to perform SSRF attacks, access internal resources, or execute arbitrary code on the server. Exploitation involves uploading a malicious PHAR-PNG file and triggering image resizing to deserialize PHAR metadata, enabling full remote code execution. Attackers could also disclose local files or perform blind SSRF via network stream wrappers.

Compliance Impact

This vulnerability could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using vulnerable OctoberCMS versions may face compliance breaches, legal penalties, and reputational damage due to potential data breaches or unauthorized system access.

Mitigation Strategies

Immediately upgrade October CMS to version 4.3.5 or later. If upgrading is not possible, implement a scheme whitelist in the getSourcePathForResize function to only allow http:// and https://. Audit template code and backend configurations for untrusted input usage in the |resize Twig filter or ResizeImages::resize() API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart