Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2026-104463 — YesWiki

HIGH

CVE-2026-104463 is a high-severity (CVSS 7) Server-Side Request Forgery (SSRF) vulnerability. No vendor fix is recorded yet; mitigation options are listed below.

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the…

Published
Oct 2, 2026
Updated
Oct 2, 2026
Affected
—
Patched
—
Exploits
None indexed
Exploitation data as of Oct 2, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2026-104463 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    Restrict outbound requests from the affected component to an allowlist of hosts, block access to link-local and internal address ranges at the network layer, and require authentication on internal services so a forged request cannot reach them unauthenticated.

Frequently Asked Questions

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.
O3 Security · Impact-Aware SCA

Is CVE-2026-104463 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-104463: YesWiki SSRF (High 7) | O3 Security