HIGH
CVE-2026-71280
CVSS
8.5
Description
go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.18%
Probability of exploitation in next 30 days
7.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.