CVE-2026-47170 HIGH

CVE-2026-47170: Garlic-Hub: SSRF vulnerability in uploadFromUrl endpoint

Vendor Garlic-Signage
Product garlic-hub
Weakness CWE-918 · SSRF
Published June 11, 2026
Last update June 13, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning, service fingerprinting, and retrieval of internal HTTP responses which are stored in the publicly accessible media pool. This issue has been patched in version 1.1.

Key dates

02Disclosure timeline

June 11, 2026 CVE published
June 13, 2026 Record updated