---
id: CVE-2026-108594
title: >-
  Mealie 3.26.0 through 3.28.0 contains a server-side request forgery
  vulnerability in the OpenID Connect avatar fetch that ignores ports when
  allowlisting the identity provider hostname
summary: >-
  Mealie 3.26.0 through 3.28.0 contains a server-side request forgery
  vulnerability in the OpenID Connect avatar fetch that ignores ports when
  allowlisting the identity provider hostname. Authenticated OIDC users who
  control their picture …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T19:16:57.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108594'
references:
  - url: 'https://github.com/mealie-recipes/mealie'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mealie-recipes/mealie/blob/v3.28.0/mealie/core/security/providers/openid_provider.py#L170-L200
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mealie-recipes/mealie/blob/v3.28.0/mealie/pkgs/safehttp/transport.py#L60-L160
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@haind/mealie-oidc-avatar-ssrf'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mealie-3.26.0-through-3.28.0-ssrf-via-oidc-picture-claim-avatar-fetch
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T19:30:07.153Z'
---

## Overview

Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
