{"id":"CVE-2026-18736","title":"Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-reso…","summary":"Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-reso…","severity":"medium","cvss":5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-918"],"published":"2026-08-03","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:35:08.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18736","references":[{"url":"https://github.com/shlinkio/shlink","label":"disclosure@vulncheck.com"},{"url":"https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/shlink-server-side-request-forgery-via-short-url-title-auto-resolution","label":"disclosure@vulncheck.com"},{"url":"https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00305,"epssPercentile":0.23452,"ingestedAt":"2026-09-09T21:22:45.522Z","slug":"CVE-2026-18736","body":"## Overview\n\nShlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}