CVE-2026-71210

MEDIUM CVSS 3.1: 5.3 EPSS 0.16%
Updated Aug 10, 2026
Mealie
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-367 (Time-of-check Time-of-use (TOCTOU))
Vendor Mealie
Public PoC No

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1