CVE-2026-62993 is a server-side request forgery (SSRF) vulnerability in Smarty, the widely used PHP template engine, affecting its {fetch} template function.
What the vulnerability does
Per the GitHub Security Advisory (GHSA-cq55-c7wv-pxmq), when a Smarty security policy is active, {fetch} validates a requested remote URL against a trusted_uri allowlist via Security::isTrustedUri(). For non-http:// schemes such as https://, the resource is then read using PHP’s file_get_contents(), which follows HTTP redirects by default. Because isTrustedUri() only validates the initial URL, an open redirect present on an otherwise-trusted host can redirect the request to a non-trusted, internal target — completely bypassing the trusted_uri policy the application relied on.
The practical exploit: an attacker who can supply or influence a {fetch} target, and who has access to an open redirect on a host already listed in trusted_uri, can cause the server to issue requests to attacker-chosen internal endpoints — the classic SSRF outcome of reaching internal-only services from an external trigger.
Fix and affected versions
Fixed in Smarty 5.8.2 (and backported to 4.5.7 for the 4.x line), per the GitHub Advisory. The fix passes a stream context that disables redirect following (follow_location => 0, max_redirects => 1) to file_get_contents() when fetching remote resources under an active security policy. Behavior is unchanged when no security policy is set, since there’s no trusted_uri allowlist to bypass in that case.
Confidence
This record traces directly to Smarty’s own GitHub Security Advisory with a clear root-cause description and confirmed fix — confidence is high, despite the CVSS score of 0 recorded in our ingested data (likely an unscored/awaiting-analysis state rather than a true zero-severity rating, given the advisory’s own SSRF classification).
Why this matters
Server-side template engines with a {fetch}-style remote-resource feature are a recurring SSRF surface, and a trusted_uri allowlist is exactly the kind of control application developers add specifically to prevent it — a bypass that defeats that control via a simple open redirect means any application relying on trusted_uri for its SSRF protection was not actually protected against a redirect-chaining attacker. Applications using Smarty’s {fetch} with an active security policy should upgrade to 5.8.2 (or 4.5.7) and additionally audit whether any host in their own trusted_uri list has an open redirect.
Frequently Asked Questions
What is CVE-2026-62993?
A server-side request forgery vulnerability in the Smarty PHP template engine, where an open redirect on a trusted host can bypass the trusted_uri allowlist for the {fetch} template function.
Which version fixes CVE-2026-62993? Smarty 5.8.2 (or 4.5.7 for the 4.x line) and later.
Is CVE-2026-62993 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from Smarty’s own GitHub Security Advisory and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.