GHSA-2fx5-pggv-6jjr · Severity: medium · Ecosystem: composer — TYPO3 Potential Open Redirect via Parsing Differences
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 LTS, 12.4.25 LTS, 13.4.3 which fix the problem described. There are no known workarounds for this vulnerability.
Conclusion & alert: CVE-2024-55892 is rated Low Risk (24.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.23%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.25% | 0.23% | -0.02% |
| 2 | 2026-06-05 | 0.19% | 0.25% | +0.07% |
| 3 | 2026-02-23 | — | 0.19% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
2.2 | 2.5 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-2fx5-pggv-6jjr · Severity: medium · Ecosystem: composer — TYPO3 Potential Open Redirect via Parsing Differences
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| typo3 | typo3 | >= 9.0.0, < 9.5.49 | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
| typo3 | typo3 | >= 10.0.0, < 10.4.48 | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
| typo3 | typo3 | >= 11.0.0, < 11.5.42 | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
| typo3 | typo3 | >= 12.0.0, < 12.4.25 | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
| typo3 | typo3 | >= 13.0.0, < 13.4.3 | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/TYPO3/typo3/security/advisories/GHSA-2fx5-pggv-6jjr | Vendor Advisory |
| https://typo3.org/security/advisory/typo3-core-sa-2025-002 | Vendor Advisory |