Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2026-101005 — October Cms

HIGH

CVE-2026-101005 is a high-severity (CVSS 7.3) Server-Side Request Forgery (SSRF) vulnerability in october_cms october cms. No vendor fix is recorded yet; mitigation options are listed below.

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection.…

Published
Sep 28, 2026
Updated
Sep 28, 2026
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 28, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Description

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.

Affected Products

1 product · 1 configurations
Application
october cmsoctober_cms
all

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every october_cms october cms deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2026-101005 yet — track the october_cms october cms advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Restrict outbound requests from the affected component to an allowlist of hosts, block access to link-local and internal address ranges at the network layer, and require authentication on internal services so a forged request cannot reach them unauthenticated. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.
O3 Security · Runtime Protection

Is CVE-2026-101005 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2026-101005: October Cms (High 7.3) | O3 Security