CVE-2026-34590 | gitroomhq postiz-app up to 2.21.3 Webhook /webhooks/ IsUrl url server-side request forgery (GHSA-wc9c-7cv8-m225)
A vulnerability, which was classified as critical, has been found in gitroomhq postiz-app up to 2.21.3. This issue affects the function IsUrl of the file /webhooks/ of the component Webhook Handler. This manipulation of the argument url causes server-side request forgery.
This vulnerability is registered as CVE-2026-34590. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.