SSRF in Koha version ≤ 25.11 (CVE-2026-26379)
Contents
SSRF in Koha version ≤ 25.11 (CVE-2026-26379)
Description and Impact
| Type | Affected Version | ?-day |
|---|---|---|
| SSRF | ≤25.11 (latest) | 0-day |
Steps to Reproduce
First, from the Dashboard interface, go to Koha Administration → Z39.50/SRU servers:

Select + New Z39.50 server

Assume the internal network is hosting an application on port 8888: nc -nvlp 8888

Fill in the information as follows:

Save.
Go to http://192.168.116.130:8080/cgi-bin/koha/cataloguing/z3950_search.pl and fill in the information as shown in the image:

Click Search.
A request is sent to the server:

- If the response is
Connection timeout, it means there is an internal service with port 8888 open:

- If there is no service listening on port 8888, the response is
Connection failed:
