Vulnerability intelligence
CVE-2026-49328
Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.
CVSS Score
5.3
Medium
EPSS — Exploit Probability
0.5%
Riskier than 40% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026
Coverage timeline
-
Apache Fesod SSRF bug CVE-2026-49328 exposes internal systemssecurityonline.info · Jun 2, 2026