CVE-2026-101005 — October Cms
HIGHCVE-2026-101005 is a high-severity (CVSS 7.3) Server-Side Request Forgery (SSRF) vulnerability in october_cms october cms. No vendor fix is recorded yet; mitigation options are listed below.
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection.…
Description
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.
Affected Products
october cmsoctober_cmsDetection & mitigation playbook
Vendor / applianceDetect
Inventory every october_cms october cms deployment and check each version against the affected-products list above.
Remediation status
No patch has shipped for CVE-2026-101005 yet — track the october_cms october cms advisory for a fixed release and apply the workarounds below in the meantime.
Mitigate without a patch
Restrict outbound requests from the affected component to an allowlist of hosts, block access to link-local and internal address ranges at the network layer, and require authentication on internal services so a forged request cannot reach them unauthenticated. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Frequently Asked Questions
Is CVE-2026-101005 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.