cvedb.io
CVE-2026-35516
MEDIUM · CVSS 5
EPSS exploitation probability: 0%
Published 2026-04-07T16:16:27.937 · Last modified 2026-06-17T10:40:42.767

Summary

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read responses from internal services (AWS IMDSv1, cloud metadata, internal APIs) by creating a link with a public URL and then updating it to a private IP. The links:check cron job makes the request server-side without IP filtering. This can expose cloud credentials, internal service data, and network topology. This vulnerability is fixed in 2.5.4.

Affected products

linkace — linkace

Does this affect you?

Add your gear to cvedb and we'll alert you only when linkace ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.