{"schema_version": "1.6.1", "id": "CVE-2026-49328", "summary": "Improper validation of user-supplied URLs leading to SSRF", "details": "Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0"}, {"fixed": "2.0.2-incubating"}]}]}], "references": [{"type": "WEB", "url": "https://github.com/apache/fesod/pull/917"}, {"type": "WEB", "url": "https://github.com/apache/fesod/releases/tag/2.0.2-incubating"}, {"type": "WEB", "url": "https://fesod.apache.org/docs/download"}, {"type": "WEB", "url": "https://lists.apache.org/thread/c1pb5b66h02p9tlrnfbwcgcz85v16fkj"}]}