CVE-2026-45082
karakeep-app karakeep
Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private network destinations, these protections could be bypassed through crafted HTTP redirect chains. By leveraging attacker-controlled redirects, an authenticated user could cause vulnerable application components to initiate requests toward internally reachable Docker network service...
- CVSS
- 7.6
- EPSS
- 0.30% 22.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.27