---
id: CVE-2026-82476
title: >-
  Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range
  from SSRF protection in its link-metadata fetcher, allowing unauthenticated
  attackers to bypass IP validation
summary: >-
  Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range
  from SSRF protection in its link-metadata fetcher, allowing unauthenticated
  attackers to bypass IP validation. Attackers can make the server request
  internal ho…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
published: '2026-08-29'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82476'
references:
  - url: 'https://github.com/usememos/memos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/usememos/memos/blob/v0.30.0/internal/httpgetter/html_meta.go
    label: disclosure@vulncheck.com
  - url: 'https://github.com/usememos/memos/issues/6099'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/memos-through-0.30.0-ssrf-via-omitted-cgnat-address-range
    label: disclosure@vulncheck.com
  - url: 'https://github.com/usememos/memos/issues/6099'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00427
epssPercentile: 0.34265
ingestedAt: '2026-08-30T12:52:24.131Z'
---

## Overview

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata services and read page titles and descriptions back.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
