CVE-2026-49328 - Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF | Apache Fesod (Incubating)Published byfesod.apache.orgon •1 min readSecurity advisory for CVE-2026-49328 regarding Server-Side Request Forgery (SSRF) in Apache Fesod (Incubating).ApacheFesodPoiOpensourceFastexcelEasyexcelannouncementsecurityCVE-2026-49328Older postLearn moreShareLegalReport