Vulnerabilities
CVE-2026-25738 - Indico has Server-Side Request Forgery (SSRF) in multiple places
CVE ID : CVE-2026-25738 Published : Feb. 19, 2026, 4:27 p.m. | 11 minutes ago Description : Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forgery. Indico makes outgoing requests to user-provides URLs in various places. This is mostly intentional and part of Indico's functionality but is never intended to let users access
CVE Details
CVE ID
Published
Feb. 19, 2026