shlink <= 5.0.1 SSRF Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- shlink (packagist)
- Affected versions
- <= 5.0.1
- Patched version
- Not yet available
An early warning has been issued for a Server-Side Request Forgery (SSRF) vulnerability in shlink versions up to and including 5.0.1. This vulnerability may allow attackers to scan internal resources.
What happened
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the automatic short URL title resolution component of shlink v5.0.1. This vulnerability allows attackers to potentially scan internal resources by supplying a crafted longUrl. The vulnerability is tracked under GHSA-P85R-X2WJ-MXQJ and CVE-2026-50887. The issue was first flagged on June 15, 2026.
The vulnerability affects shlink versions up to and including 5.0.1. There is currently no patched version available. Users of shlink are advised to upgrade to a version that patches this vulnerability as soon as it becomes available and to review their internal resource access controls.
What to do about it
- Monitor the primary sources for updates on a patched version of shlink.
- Review and strengthen internal resource access controls to mitigate potential SSRF attacks.
- Stay informed about the vulnerability by consulting the primary sources listed below.
How 0Day would have caught this
shlink is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using shlink version 5.0.1 or earlier, you may be affected by this vulnerability.
What should I do right now?
Monitor the primary sources for updates on a patched version of shlink and review your internal resource access controls.
Is there a patched version available?
No official fix has been published yet. Monitor the sources below for updates.