PACKAGIST · JUNE 2026 · EARLY WARNING

shlink <= 5.0.1 SSRF Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
shlink (packagist)
Affected versions
<= 5.0.1
Patched version
Not yet available
GHSA-P85R-X2WJ-MXQJ

An early warning has been issued for a Server-Side Request Forgery (SSRF) vulnerability in shlink versions up to and including 5.0.1. This vulnerability may allow attackers to scan internal resources.

What happened

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the automatic short URL title resolution component of shlink v5.0.1. This vulnerability allows attackers to potentially scan internal resources by supplying a crafted longUrl. The vulnerability is tracked under GHSA-P85R-X2WJ-MXQJ and CVE-2026-50887. The issue was first flagged on June 15, 2026.

The vulnerability affects shlink versions up to and including 5.0.1. There is currently no patched version available. Users of shlink are advised to upgrade to a version that patches this vulnerability as soon as it becomes available and to review their internal resource access controls.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If shlink is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using shlink version 5.0.1 or earlier, you may be affected by this vulnerability.

What should I do right now?

Monitor the primary sources for updates on a patched version of shlink and review your internal resource access controls.

Is there a patched version available?

No official fix has been published yet. Monitor the sources below for updates.

Sources

Join the 0Day waitlist →

← Back to all threats