← All CVEs NewScan detects
high

CVE-2026-77348

Wallos SSRF through HTTP proxy environment variables - the incomplete fix for CVE-2026-33407

Severity
high
Affected product
Wallos
Affected versions
Wallos < 5.0.0
Fixed in
Wallos 5.0.0
Added to NewScan
2026-09-01
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Wallos from its response and reports this CVE when the detected version falls inside the affected range below.

The third fixed-release bound of the 2026-09-01 Wallos batch, kept separate precisely because it is the one a 4.9.6+ install still has: the 4.9.x fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc) left the proxy path reachable and was only completed in 5.0.0. Deliberately NO lower bound, which is the honest under-specification: the advisory dates the flawed fix by GHSA and not by release, so a `ge` here would be invented - the cost is that a pre-33407 build is told about a fix it never had, which is true of every CVE in this file for an ancient install. OOB-shaped and version-match only, like the SSRF ids in the 4.9.6 row.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →