CVE-2026-77348
Wallos SSRF through HTTP proxy environment variables - the incomplete fix for CVE-2026-33407
- Severity
- high
- Affected product
- Wallos
- Affected versions
- Wallos < 5.0.0
- Fixed in
- Wallos 5.0.0
- Added to NewScan
- 2026-09-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Wallos from its response and reports this CVE when the detected version falls inside the affected range below.
The third fixed-release bound of the 2026-09-01 Wallos batch, kept separate precisely because it is the one a 4.9.6+ install still has: the 4.9.x fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc) left the proxy path reachable and was only completed in 5.0.0. Deliberately NO lower bound, which is the honest under-specification: the advisory dates the flawed fix by GHSA and not by release, so a `ge` here would be invented - the cost is that a pre-33407 build is told about a fix it never had, which is true of every CVE in this file for an ancient install. OOB-shaped and version-match only, like the SSRF ids in the 4.9.6 row.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →