lemmy_routes
Activity
- Latest release
- 2y ago
- Total releases
- 59
- Cadence
- ~3 days
- Last 12 months
- 0
Details
- License
- AGPL-3.0
- First release
- Jul 24, 2021
| Version | Released | |
|---|---|---|
0.19.1-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.19.1-rc.1
unknown
Dependencies (18)
+ 10 more |
|
0.18.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.2
unknown
Dependencies (19)
+ 11 more |
|
0.18.2-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.2-rc.2
unknown
Dependencies (19)
+ 11 more |
|
0.18.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.1
unknown
Dependencies (19)
+ 11 more |
|
0.18.1-rc.10
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.1-rc.10
unknown
Dependencies (19)
+ 11 more |
|
0.18.1-rc.9
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.1-rc.9
unknown
Dependencies (19)
+ 11 more |
|
0.18.1-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.1-rc.2
unknown
Dependencies (19)
+ 11 more |
|
0.18.0
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.0
unknown
Dependencies (19)
+ 11 more |
|
0.18.0-rc.8
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.0-rc.8
unknown
Dependencies (19)
+ 11 more |
|
0.18.0-rc.4
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.18.0-rc.4
unknown
Dependencies (19)
+ 11 more |
|
0.17.4
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.4
unknown
Dependencies (19)
+ 11 more |
|
0.17.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.3
unknown
Dependencies (19)
+ 11 more |
|
0.17.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.2
unknown
Dependencies (19)
+ 11 more |
|
0.17.2-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.2-rc.2
unknown
Dependencies (19)
+ 11 more |
|
0.17.2-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.2-rc.1
unknown
Dependencies (19)
+ 11 more |
|
0.17.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.1
unknown
Dependencies (19)
+ 11 more |
|
0.17.0
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.17.0
unknown
Dependencies (19)
+ 11 more |
|
0.16.7
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.7
unknown
Dependencies (21)
+ 13 more |
|
0.16.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.3
unknown
Dependencies (24)
+ 16 more |
|
0.16.3-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.3-rc.1
unknown
Dependencies (24)
+ 16 more |
|
0.16.2-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.2-rc.1
unknown
Dependencies (24)
+ 16 more |
|
0.16.1-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.1-rc.1
unknown
Dependencies (24)
+ 16 more |
|
0.16.0
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.0
unknown
Dependencies (24)
+ 16 more |
|
0.16.0-rc.4
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.0-rc.4
unknown
Dependencies (24)
+ 16 more |
|
0.16.0-rc.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.0-rc.3
unknown
Dependencies (24)
+ 16 more |
|
0.16.0-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.16.0-rc.2
unknown
Dependencies (24)
+ 16 more |
|
0.15.4
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.4
unknown
Dependencies (25)
+ 17 more |
|
0.15.4-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.4-rc.1
unknown
Dependencies (25)
+ 17 more |
|
0.15.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.2
unknown
Dependencies (25)
+ 17 more |
|
0.15.2-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.2-rc.1
unknown
Dependencies (25)
+ 17 more |
|
0.15.0-rc.7
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.0-rc.7
unknown
Dependencies (25)
+ 17 more |
|
0.15.0-rc.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.15.0-rc.3
unknown
Dependencies (25)
+ 17 more |
|
0.14.5
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.5
unknown
Dependencies (21)
+ 13 more |
|
0.14.5-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.5-rc.2
unknown
Dependencies (21)
+ 13 more |
|
0.14.5-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.5-rc.1
unknown
Dependencies (21)
+ 13 more |
|
0.14.4-rc.4
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.4-rc.4
unknown
Dependencies (21)
+ 13 more |
|
0.14.4-rc.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.4-rc.3
unknown
Dependencies (21)
+ 13 more |
|
0.14.3
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.3
unknown
Dependencies (21)
+ 13 more |
|
0.14.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.2
unknown
Dependencies (21)
+ 13 more |
|
0.14.2-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.2-rc.1
unknown
Dependencies (21)
+ 13 more |
|
0.14.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.1
unknown
Dependencies (22)
+ 14 more |
|
0.14.0
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (22)
+ 14 more |
|
0.14.0-rc.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.0-rc.2
unknown
Dependencies (22)
+ 14 more |
|
0.14.0-rc.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.14.0-rc.1
unknown
Dependencies (22)
+ 14 more |
|
0.13.5
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.13.5
unknown
Dependencies (23)
+ 15 more |
|
0.13.5-rc.7
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.13.5-rc.7
unknown
Dependencies (22)
+ 14 more |
|
0.13.5-rc.6
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.13.5-rc.6
unknown
Dependencies (22)
+ 14 more |
|
0.13.1
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.13.1
unknown
Dependencies (23)
+ 15 more |
|
0.13.0
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (23)
+ 15 more |
|
0.12.2
unknown
1 CVE
CVE-2026-29178
GHSA-jvxv-2jjp-jxc3
Mar 04, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
Network
Low
None
None
SummaryThe Affected code
The This endpoint does not require authentication (no PoC
The response from the internal URL is streamed back to the attacker through pict-rs and Lemmy. ImpactAn unauthenticated attacker can:
Suggested FixValidate the
Fixed in
0.19.16
References Updated Mar 06, 2026 · Source: OSV.dev |
0.12.2
unknown
Dependencies (22)
+ 14 more |