CVE-2026-33644 | Lychee up to 7.5.1 Domain Name PhotoUrlRule.php filter_var host server-side request forgery (GHSA-5245-4p8c-jwff)
A vulnerability classified as critical was found in Lychee up to 7.5.1. This vulnerability affects the function filter_var of the file PhotoUrlRule.php of the component Domain Name Handler. Executing a manipulation of the argument host can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-33644. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.