CVE-2026-39087: Server-Side Request Forgery (SSRF) in ntfy via Unanchored Web Push Endpoint Regex Affected Software Product: ntfy (https://github.com/binwiederhier/ntfy) Affected Versions: < 2.22.0 Fixed Version: 2.22.0 Vulnerability Type Server-Side Request Forgery (SSRF) — CWE-918