CVE-2026-108594
Deferred Deferred - Pending Action

Server-Side Request Forgery in Mealie via OpenID Connect

Vulnerability report for CVE-2026-108594, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mealie-recipes mealie 3.26.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Mealie versions 3.26.0 through 3.28.0. When OpenID Connect (OIDC) is enabled, Mealie fetches the user's avatar from a URL provided in the OIDC claim. The vulnerability occurs because Mealie only checks the hostname for allowlisting and ignores the port, allowing authenticated users to make the server send requests to arbitrary ports on the provider's internal network by setting their picture URL to a malicious value like http://idp.internal:2375/. The SSRF protection fails because it treats the allowlisted hostname as covering all ports at that IP address.

The attack is blind since the response is stored as the avatar and not returned to the attacker. The root cause is improper validation of the avatar URL, which bypasses SSRF protections designed to block access to private or internal addresses.

Detection Guidance

Check Mealie logs for outbound HTTP requests to unexpected internal IP addresses or ports during OIDC login. Monitor network traffic for connections to private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) from the Mealie server. Inspect OIDC provider configuration for allowlisted hostnames with open ports.

Impact Analysis

If you are an administrator or user of a vulnerable Mealie instance with OIDC enabled, an attacker who can authenticate via OIDC could exploit this to force your server to send requests to internal systems or services on arbitrary ports. This could lead to internal network reconnaissance, unauthorized access to internal resources, or data exfiltration if combined with other vulnerabilities. The impact is limited by the fact that the attack is blind and requires authenticated OIDC access.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing internal network resources or sensitive data to unauthorized access. GDPR requires protecting personal data and ensuring secure processing, while HIPAA mandates safeguards for protected health information. An SSRF vulnerability that allows internal network access could lead to breaches of confidentiality or unauthorized data exposure, violating these regulations. Organizations using vulnerable Mealie versions should address this issue to maintain compliance.

Mitigation Strategies

Upgrade Mealie to a patched version beyond 3.28.0. If upgrading is not possible, restrict OIDC avatar fetching to trusted domains and disable internal network access. Review and tighten SSRF protections in transport.py to validate ports alongside hostnames.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108594. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart