Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata services and read page titles and descriptions back.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata services and read page titles and descriptions back. | |
| Title | Memos through 0.30.0 SSRF via Omitted CGNAT Address Range | |
| First Time appeared |
Usememos
Usememos memos |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:36.039Z
Reserved: 2026-08-29T14:11:15.036Z
Link: CVE-2026-82476
No data.
Status : Received
Published: 2026-08-29T17:18:00.197
Modified: 2026-08-29T17:18:00.197
Link: CVE-2026-82476
No data.
OpenCVE Enrichment
No data.
Weaknesses