THREAT OPS › Threat News › [GHSA] GHSA-8x3q-jpjh-qh5c (high) — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
[GHSA] GHSA-8x3q-jpjh-qh5c (high) — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
GHSA-8x3q-jpjh-qh5c Severity: high CVE: CVE-2026-81889
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
poc.zip ## Summary
elFinder 2.1.69 is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass when PHP cURL is unavailable and URL uploads use the `fsock_get_contents()` fallbac
MITRE ATT&CK techniques
Indicators of compromise
- 8f2c3ffafcdd52cf4515f1eec172f4eee44552adsha1
- CVE-2026-81889cve
- http://127.0.0.1:8081/poc/index.htmlurl
- http://rebind.test:9001/secret.txturl
- http://rebind.test:9001/redirect-secreturl
- marcolunardi90@gmail.comemail
- 203.0.113.10ipv4
Original source: https://github.com/advisories/GHSA-8x3q-jpjh-qh5c