Compound WireTHE STANDUP31 August 2026
elFinder
DNS REBINDING BEATS THE SSRF CHECK
elFinder SSRF check tricked by DNS rebinding on its cURL fallback
CVE-2026-81889: elFinder 2.1.69's SSRF check can be bypassed by DNS rebinding, a hostname that resolves to an allowed public IP at validation and to loopback or a private range at fetch. Only on the fsock_get_contents() fallback, which runs when PHP cURL is unavailable. #software