CVE-2026-82081

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

  • Published Aug 28, 2026
  • CVSS 6.4 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-82081 at the National Vulnerability Database