CVE-2026-105861: Payload external upload trust validation issue
## Impact Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient. **You are affected if:** - You have enabled external URL-based upload retrieval, where authenticated requests can trigger it. ## Patches Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination. Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds It is recommended to update all Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. If you cannot, a valid workaround exists: - Disable external URL-based upload retrieval where practical. - If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests. - Restrict access to the affected upload functionality.
Recommended action
Recommended action
Upgrade affected packages to a patched version: payload 3.90.0, payload 4.0.0-canary.34.
Technical details
- Vendor
- Not specified
- Product
- payload
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source