Indico, Server-Side Request Forgery, CVE-2026-25738 (Moderate) -DC-Oct2026-2992

Listen to this Post

This vulnerability arises because Indico handles outgoing HTTP requests to external URLs provided by users as part of its regular event-management features. Although input checks are intended to prevent access to internal infrastructure, a security edge case bypasses these controls. Because previous validation logic fails to fully restrict specific crafted inputs, authenticated users with specific permissions can force the underlying application server to query restricted internal locations such as localhost addresses or cloud provider metadata services. This flaw allows malicious actors or untrusted event managers to pivot internally, retrieve sensitive cloud environment configurations, or access protected services that are otherwise shielded behind local network interfaces.

DailyCVE Form:

Platform: Indico
Version: Prior to 3.3.13
Vulnerability : SSRF
Severity: Moderate
date: 2026-10-08

Prediction: Already patched

What Undercode Say:

Bash Commands and Codes

export http_proxy="http://proxy.internal:8080"
export https_proxy="http://proxy.internal:8080"
systemctl restart indico-uwsgi indico-celery

Exploit: (Educational Purposes!)

import requests
target_url = "http://169.254.169.254/latest/meta-data/"
crafted_input = "http://localhost:80/secret"
Simulating SSRF request evaluation flaw
response = requests.get(crafted_input, timeout=5)
print(response.text)

Protection: from this CVE

Upgrade the Indico platform immediately to version 3.3.13 or later. Configure explicit proxy environment variables (http_proxy and https_proxy) across both `indico-uwsgi` and `indico-celery` worker services to route and restrict all outbound server requests. Restrict administrative event creation roles to fully trusted personnel.

Impact

Allows authenticated event organizers to exploit edge-case URL validation gaps, triggering Server-Side Request Forgery (SSRF) against internal services, loopback interfaces, or cloud instance metadata endpoints to leak sensitive configuration data.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top