Skip to main content
QUIETLYTIC
Vulnerability

Smarty SSRF (CVE-2026-62993)

CVE-2026-62993 lets an open redirect on a trusted host bypass Smarty's trusted_uri policy for {fetch}, enabling server-side request forgery to internal targets, fixed in 5.8.2.

CVE-2026-62993
Threat Level
LOW
CVSS
0.0
Status
Monitored
Confidence
High
Affected Products
Smarty (PHP template engine)

CVE-2026-62993 is a server-side request forgery (SSRF) vulnerability in Smarty, the widely used PHP template engine, affecting its {fetch} template function.

What the vulnerability does

Per the GitHub Security Advisory (GHSA-cq55-c7wv-pxmq), when a Smarty security policy is active, {fetch} validates a requested remote URL against a trusted_uri allowlist via Security::isTrustedUri(). For non-http:// schemes such as https://, the resource is then read using PHP’s file_get_contents(), which follows HTTP redirects by default. Because isTrustedUri() only validates the initial URL, an open redirect present on an otherwise-trusted host can redirect the request to a non-trusted, internal target — completely bypassing the trusted_uri policy the application relied on.

The practical exploit: an attacker who can supply or influence a {fetch} target, and who has access to an open redirect on a host already listed in trusted_uri, can cause the server to issue requests to attacker-chosen internal endpoints — the classic SSRF outcome of reaching internal-only services from an external trigger.

Fix and affected versions

Fixed in Smarty 5.8.2 (and backported to 4.5.7 for the 4.x line), per the GitHub Advisory. The fix passes a stream context that disables redirect following (follow_location => 0, max_redirects => 1) to file_get_contents() when fetching remote resources under an active security policy. Behavior is unchanged when no security policy is set, since there’s no trusted_uri allowlist to bypass in that case.

Confidence

This record traces directly to Smarty’s own GitHub Security Advisory with a clear root-cause description and confirmed fix — confidence is high, despite the CVSS score of 0 recorded in our ingested data (likely an unscored/awaiting-analysis state rather than a true zero-severity rating, given the advisory’s own SSRF classification).

Why this matters

Server-side template engines with a {fetch}-style remote-resource feature are a recurring SSRF surface, and a trusted_uri allowlist is exactly the kind of control application developers add specifically to prevent it — a bypass that defeats that control via a simple open redirect means any application relying on trusted_uri for its SSRF protection was not actually protected against a redirect-chaining attacker. Applications using Smarty’s {fetch} with an active security policy should upgrade to 5.8.2 (or 4.5.7) and additionally audit whether any host in their own trusted_uri list has an open redirect.

Frequently Asked Questions

What is CVE-2026-62993? A server-side request forgery vulnerability in the Smarty PHP template engine, where an open redirect on a trusted host can bypass the trusted_uri allowlist for the {fetch} template function.

Which version fixes CVE-2026-62993? Smarty 5.8.2 (or 4.5.7 for the 4.x line) and later.

Is CVE-2026-62993 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from Smarty’s own GitHub Security Advisory and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Smarty (GitHub Security Advisory)
02 National Vulnerability Database (NVD)

Related intelligence


Analyst tools