CVE-2026-107394: Server-Side Request Forgery Bypass via Parser Differential in Indico
Vulnerability ID: CVE-2026-107394
CVSS Score: 6.8
Published: 2026-10-08
An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.
TL;DR
A parser mismatch between Python's urllib.parse.urlsplit and HTTP client libraries allows event organizers to bypass local network blocklists using backslash characters in URLs.
Technical Details
- CWE ID: CWE-918
- Attack Vector: Network
- CVSS Score: 6.8 (Medium)
- EPSS Score: 0.00%
- Impact: Server-Side Request Forgery
- Exploit Status: Proof of Concept / Test Case Available
- KEV Status: Not Listed
Affected Systems
- Indico event management system
-
Indico: < 3.3.13 (Fixed in:
3.3.13)
Mitigation Strategies
- Upgrade to Indico version 3.3.13 or newer
- Implement WAF rules to detect backslash characters in URL parameters
- Configure firewall rules to restrict the Indico server's access to local loopback addresses
Remediation Steps:
- Identify instances running Indico versions prior to 3.3.13.
- Apply the patch or update using the package manager to version 3.3.13.
- Restart the Indico application service to apply changes.
- Verify the fix by testing URL inputs with backslash characters in the event configuration interfaces.
References
Read the full report for CVE-2026-107394 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)