CVE-2026-25493 – Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
CVE ID : CVE-2026-25493
Published : Feb. 9, 2026, 7:36 p.m. | 44 minutes ago
Description : Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An attacker can bypass all SSRF protections by hosting a redirect that points to cloud metadata endpoints or any internal IP addresses. This issue is patched in versions 4.16.18 and 5.8.22.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more…