
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28423 is a Server-Side Request Forgery (SSRF) vulnerability in Statamic CMS, a Laravel and Git-powered content management system. When the Glide image manipulation feature is configured in insecure mode (a non-default setting), an unauthenticated attacker can abuse the image proxy to force the server to send HTTP requests to arbitrary URLs — either via direct URL manipulation or through the watermark feature. Affected versions include all Statamic releases prior to 5.73.11 (5.x branch) and 6.0.0 through 6.3.x (6.x branch, fixed in 6.4.0). The vulnerability was disclosed on February 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.8 (Moderate) per the GitHub Security Advisory, though Feedly's data notes an alternative score of 8.6 based on a slightly different vector (GitHub Advisory, Statamic Advisory).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where the Glide image proxy fails to sufficiently validate or restrict the destination URLs it fetches when operating in insecure mode. In this non-default configuration, the image proxy accepts externally supplied URLs — either as direct image source parameters or as watermark URLs — without adequate allowlist enforcement, enabling the server to be directed to make outbound HTTP requests to attacker-controlled destinations. The fix, implemented via the "External Glide URL validation" change (PR #14101 by @jasonvarga), adds proper URL validation to restrict which external hosts the proxy may contact. The vulnerability requires no privileges and no user interaction, but exploitation is contingent on the administrator having explicitly enabled insecure mode for Glide (GitHub Advisory, v5.73.11 Release).
Successful exploitation allows an unauthenticated attacker to leverage the Statamic server as a proxy to reach internal network services, cloud metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254), and other hosts accessible from the server's network context. The primary impact is a high confidentiality loss — sensitive data such as cloud credentials, internal API tokens, and configuration details can be exfiltrated — while integrity and availability are not directly affected. This SSRF can facilitate lateral movement into internal infrastructure or enable privilege escalation by harvesting cloud IAM credentials from metadata services (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.025% (7th percentile), indicating a low near-term exploitation probability. Exploitation is further constrained by the requirement that the target Statamic instance must have Glide configured in insecure mode, which is not the default configuration (GitHub Advisory).
/img) with an external URL parameter — a successful image fetch or HTTP response indicates the vulnerable configuration is active.GET /img?src=http://169.254.169.254/latest/meta-data/iam/security-credentials/ to probe cloud metadata services.10.x.x.x, 172.16.x.x, 192.168.x.x) or cloud metadata IPs (169.254.169.254, fd00:ec2::254); unexpected DNS lookups or HTTP connections to attacker-controlled external hosts originating from the web server./img) with external or internal URLs as src or watermark parameters; repeated or automated requests to the image proxy with varying URL targets.netstat, ss, or endpoint detection tools.Statamic has released patched versions 5.73.11 (for the 5.x branch) and 6.4.0 (for the 6.x branch), both published on February 27, 2026, which include external Glide URL validation to restrict arbitrary outbound requests (v5.73.11 Release, v6.4.0 Release). As an immediate workaround, administrators should disable Glide insecure mode or revert to the default secure configuration if the feature is not required. Additionally, network-level controls — such as firewall rules blocking the web server from reaching internal services and cloud metadata endpoints — can significantly reduce the exploitability and impact of this vulnerability (GitHub Advisory).
The vulnerability was reported by security researcher dxlerYT and disclosed by Statamic maintainer jasonvarga via the GitHub Security Advisory program on February 27, 2026 (Statamic Advisory). No significant broader media coverage or notable community commentary beyond the standard advisory tracking has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."