Server-side Request Forgery (SSRF) Affecting indico package, versions [,3.3.10)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-INDICO-15308667
  • published19 Feb 2026
  • disclosed17 Feb 2026
  • creditrahulgovind,Vasilii Ermilov,Yue (Knox) Liu

Introduced: 17 Feb 2026

CVE-2026-25738  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade indico to version 3.3.10 or higher.

Overview

indico is a conference lifecycle management and meeting/lecture scheduling tool.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in is_private_url() in util/network.py. A user can access internal network resources or sensitive endpoints by supplying malicious URLs.

Workaround

This vulnerability can be mitigated by configuring the http_proxy and https_proxy environment variables to proxy outgoing requests.

CVSS Base Scores

version 4.0
version 3.1