CVE-2026-52769 | CVSS: 8.3 | 严重级别: HIGH
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route – exposed publicly with acl:"public" – accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a server-side HTTP GET to that URL, before any cryptographic verification or URL validation. An unauthenticated remote attacker can therefore make YesWiki issue arbitrary outbound HTTP requests to any host the server can reach – internal services, cloud-metadata endpoints (169.254.16
参考链接:
• http://github.com/YesWiki/yeswiki/commit/87e627f33e79879827a3669fee2aa1244612c48
• https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6
• https://github.com/YesWiki/yeswiki/security/advisories/GHSA-vw42-752g-5mrp
📌 数据来源: NVD 官方