Skip to main content
Loading…
    CVE-2026-33644 — Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be bypassed using DNS rebinding. The IP validation check (line 86-89) only ac — CVE Database · The Intelligence Room