Back

MEDIUM

Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)

Published Aug 31, 2026

Description

Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting the SMTP host of their personal email notifications to an internal IP. The per-user notification settings endpoint (endpoints/notifications/saveemailnotifications.php) performs no SSRF validation, and the notification cron (endpoints/cronjobs/sendnotifications.php) feeds that user-controlled host straight into PHPMailer ($mail->Host = $email['smtpAddress']). When the user's subscription notification fires, the server connects to the chosen host:port. This issue has been patched in version 5.0.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 31, 2026
Updated Sep 1, 2026
Reserved Aug 20, 2026

CISA Vulnrichment

Updated Sep 1, 2026

NVD

Status Deferred
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Aug 31, 2026
Updated Sep 1, 2026

GitHub

No data