CVEs classified under CWE-777, newest first.
1 CVERSS
CVE-2026-39087
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.