CVE-2026-25494 | Craft CMS up to 5.8.21 filter_var server-side request forgery (GHSA-m5r2-8p9x-hp5m)
A vulnerability was found in Craft CMS up to 5.8.21. It has been classified as critical. This impacts the function filter_var. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-25494. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.