CVE-2026-42181: CWE-918: Server-Side Request Forgery (SSRF) in LemmyNet lemmy
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the default StoreLinkPreviews image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked against internal IP ranges, the extracted og:image URL is not subject to the same restriction. As a result, an authenticated low-privileged user can submit an attacker-controlled public page whose Open Graph image points to an internal image endpoint. Lemmy will fetch that internal image server-side and store a local thumbnail that can then be served back to users. This issue has been patched in version 0.19.18.
AI Analysis
Technical Summary
Lemmy, a fediverse link aggregator and forum software, prior to version 0.19.18, performs metadata fetching for user-submitted URLs including downloading preview images through a local image service (pict-rs). The top-level URL is checked against internal IP ranges to prevent SSRF, but the Open Graph image URL (og:image) extracted from the page is not subjected to the same validation. This allows an authenticated user with low privileges to submit a public page whose og:image points to an internal network resource. Lemmy then fetches this internal image server-side, stores a local thumbnail, and serves it back to users. This SSRF vulnerability is identified as CWE-918 and has a CVSS 3.1 base score of 6.5 (medium severity). The issue is fixed in Lemmy version 0.19.18.
Potential Impact
An authenticated low-privileged user can exploit this vulnerability to make the Lemmy server perform unauthorized requests to internal network resources by controlling the og:image URL of a submitted post. This can lead to unauthorized access to internal services or information disclosure within the internal network. The vulnerability does not impact confidentiality of the Lemmy server itself directly but can expose internal endpoints to the attacker indirectly. There is no indication of impact on integrity or availability.
Mitigation Recommendations
This vulnerability has been patched in Lemmy version 0.19.18. Users and administrators should upgrade to version 0.19.18 or later to remediate this issue. Since the vendor advisory or patch links are not explicitly provided, confirm the upgrade from official Lemmy release notes or repositories. No additional mitigation steps are indicated or required beyond applying the official patch.
CVE-2026-42181: CWE-918: Server-Side Request Forgery (SSRF) in LemmyNet lemmy
Description
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the default StoreLinkPreviews image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked against internal IP ranges, the extracted og:image URL is not subject to the same restriction. As a result, an authenticated low-privileged user can submit an attacker-controlled public page whose Open Graph image points to an internal image endpoint. Lemmy will fetch that internal image server-side and store a local thumbnail that can then be served back to users. This issue has been patched in version 0.19.18.
CVSS v3.1
Score 6.5medium
Affected software
pkg:cargo/github/LemmyNet/lemmyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Lemmy, a fediverse link aggregator and forum software, prior to version 0.19.18, performs metadata fetching for user-submitted URLs including downloading preview images through a local image service (pict-rs). The top-level URL is checked against internal IP ranges to prevent SSRF, but the Open Graph image URL (og:image) extracted from the page is not subjected to the same validation. This allows an authenticated user with low privileges to submit a public page whose og:image points to an internal network resource. Lemmy then fetches this internal image server-side, stores a local thumbnail, and serves it back to users. This SSRF vulnerability is identified as CWE-918 and has a CVSS 3.1 base score of 6.5 (medium severity). The issue is fixed in Lemmy version 0.19.18.
Potential Impact
An authenticated low-privileged user can exploit this vulnerability to make the Lemmy server perform unauthorized requests to internal network resources by controlling the og:image URL of a submitted post. This can lead to unauthorized access to internal services or information disclosure within the internal network. The vulnerability does not impact confidentiality of the Lemmy server itself directly but can expose internal endpoints to the attacker indirectly. There is no indication of impact on integrity or availability.
Mitigation Recommendations
This vulnerability has been patched in Lemmy version 0.19.18. Users and administrators should upgrade to version 0.19.18 or later to remediate this issue. Since the vendor advisory or patch links are not explicitly provided, confirm the upgrade from official Lemmy release notes or repositories. No additional mitigation steps are indicated or required beyond applying the official patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-25T01:53:21.582Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fe4242cbff5d8610241d71
Added to database: 05/08/2026, 20:06:26 UTC
Last enriched: 05/16/2026, 10:53:11 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.