CVE-2026-39087

· NIST NVD ↗

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression.

CRITICAL
CVSS severity
9.8
CVSS base score
2026-04-23
Published

CWE codes

CWE-94

Sources