THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8x3q-jpjh-qh5c (high) — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

[GHSA] GHSA-8x3q-jpjh-qh5c (high) — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

highgithub_advisoriesPublished 2026-08-31

GHSA-8x3q-jpjh-qh5c Severity: high CVE: CVE-2026-81889

elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

poc.zip ## Summary

elFinder 2.1.69 is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass when PHP cURL is unavailable and URL uploads use the `fsock_get_contents()` fallbac

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8x3q-jpjh-qh5c