Back

HIGH

Postiz allows header mutation in middleware facilitates resulting in SSRF

Published Jul 11, 2025

Description

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from the server hosting the Postiz application. This vulnerability is fixed in 1.62.3.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 11, 2025
Updated Jul 11, 2025
Reserved Jul 7, 2025
CISA Vulnrichment
Updated Jul 11, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 11, 2025
Updated Jul 11, 2025
Exploited since n/a
EUVD-2025-21168