CVE-2026-33081 | PinchTab up to 0.8.2 Internal Service /download validateDownloadURL server-side request forgery
A vulnerability was found in PinchTab up to 0.8.2 and classified as critical. This issue affects the function validateDownloadURL of the file /download of the component Internal Service. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2026-33081. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.