A vulnerability labeled as problematic has been found in s9y Serendipity up to 2.5.x. The affected element is the function
serendipity_url_allowed. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-73629. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.