Security Advisory

CVE-2026-33407

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-24 17:40:58
Last updated 2026-03-26 19:52:13
Assigner GitHub_M
State PUBLISHED

Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search terms, which can be controlled by attackers to trigger outbound requests to arbitrary domains. This issue has been patched in version 4.7.0.