phanan/koel
Music streaming solution that works.
Activity
- Latest release
- 1d ago
- Total releases
- 181
- Cadence
- ~3 days
- Last 12 months
- 35
Reach
- Stars
- 17.2k
Details
- License
- MIT
- First release
- Dec 18, 2015
| Version | Released | |
|---|---|---|
v9.12.0
minor
|
v9.12.0
minor
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
v9.11.3
patch
|
v9.11.3
patch
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
v9.11.2
patch
|
v9.11.2
patch
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
v9.11.1
patch
|
v9.11.1
patch
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
v9.11.0
minor
|
v9.11.0
minor
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
v9.10.1
patch
| ||
v9.10.0
minor
| ||
v9.9.1
patch
| ||
v9.9.0
minor
| ||
v9.8.0
minor
|
v9.8.0
minor
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
v9.7.1
patch
| ||
v9.7.0
minor
3 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v9.7.0
minor
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
v9.6.0
minor
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.5.0
minor
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.4.2
patch
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.4.1
patch
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.4.0
minor
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v9.4.0
minor
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
v9.3.6
patch
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v9.3.6
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
v9.3.5
patch
6 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.3.4
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.3.3
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.3.2
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.3.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.3.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.2.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v9.2.1
patch
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
v9.2.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.1.2
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.1.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.1.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v9.0.0
major
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v9.0.0
major
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
v8.3.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v8.3.1
patch
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
v8.3.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v8.2.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v8.1.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v8.0.0
major
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.15.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.15.1
patch
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
v7.15.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.14.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.14.0
minor
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
v7.13.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.13.0
minor
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
v7.12.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.12.0
minor
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v7.11.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.10.4
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.10.3
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.10.2
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.10.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.10.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.9.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.9.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v7.8.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.8.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v7.8.0
minor
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
| ||
v7.7.1
patch
7 CVEs
CVE-2026-54494
GHSA-rjg7-r26h-cfp2
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Medium
Network
Low
Low
None
SummaryKoel's outbound-URL guard The guard is the only SSRF defense in front of This is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata. Vulnerable code
The sink,
Attack scenario / How input reaches the sink
Proof of concept(a) Guard-predicate proof (PHP 8.5, the exact
|
v7.7.1
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|