Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisory

Apache Fesod SSRF Flaw in UrlImageConverter Patched

Updated 21d agoFirst seen Jun 1, 20262 sources

Apache disclosed CVE-2026-49328, an important-severity server-side request forgery (SSRF) vulnerability in Apache Fesod (Incubating) affecting the fesod-sheet package before version 2.0.2-incubating. The flaw resides in the UrlImageConverter component, where improper validation of user-supplied image URLs can cause the server to make outbound requests to internal or otherwise restricted resources. The issue was reported by Xu Han and is tracked in Apache Fesod issue or pull request #917.

The vulnerability could let attackers probe enterprise backend systems or private cloud endpoints that are not directly exposed to the internet, increasing the risk of internal network access and information exposure. Apache has released version 2.0.2-incubating to remediate the bug with stricter validation of user-supplied parameters, and defenders are being urged to upgrade promptly; where immediate patching is not possible, restricting unusual outbound server connections can help reduce exposure.

Share:
Apache Fesod SSRF Flaw in UrlImageConverter Patched
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 1, 202622d ago

Apache releases Fesod 2.0.2-incubating to fix CVE-2026-49328

Apache maintainers released version 2.0.2-incubating to remediate CVE-2026-49328 by tightening validation of user-supplied parameters in the affected component. Apache recommended upgrading to this version to address the SSRF issue.

oss-sec: CVE-2026-49328: Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF

Apache Fesod SSRF vulnerability CVE-2026-49328 disclosed

Apache disclosed CVE-2026-49328, an important-severity server-side request forgery flaw in the UrlImageConverter component of the fesod-sheet package affecting versions before 2.0.2-incubating. The issue can cause outbound requests to internal or otherwise restricted resources via improperly validated user-supplied image URLs.

oss-sec: CVE-2026-49328: Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.