CVE-2026-35461 | papra-hq papra up to 26.3.x server-side request forgery (GHSA-cjw7-qg95-58mq)
A vulnerability, which was classified as critical, was found in papra-hq papra up to 26.3.x. The affected element is an unknown function. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-35461. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.