CWE-918
AllowedServer-Side Request Forgery (SSRF)
Abstraction: Base · Status: Incomplete
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
6104 vulnerabilities reference this CWE, most recent first.
CVE-2026-101005 (GCVE-0-2026-101005)
Vulnerability from cvelistv5 – Published: 2026-09-28 06:00 – Updated: 2026-09-28 12:50- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410875 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410875/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101005 | third-party-advisory |
| https://vuldb.com/submit/922294 | third-party-advisory |
| https://github.com/octobercms/october/security/ad… | related |
| https://github.com/0xGenesi/CVE/blob/main/October… | exploit |
| https://github.com/octobercms/october/releases/ta… | patch |
| https://www.cybersecurity-help.cz/vdb/vulns/149488/ | related |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | October CMS |
Affected:
4.3.0
Affected: 4.3.1 Affected: 4.3.2 Affected: 4.3.3 Affected: 4.3.4 Unaffected: 4.3.5 cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101005",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:49:57.801754Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:50:08.482Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:*"
],
"modules": [
"SSRF Protection"
],
"product": "October CMS",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "4.3.0"
},
{
"status": "affected",
"version": "4.3.1"
},
{
"status": "affected",
"version": "4.3.2"
},
{
"status": "affected",
"version": "4.3.3"
},
{
"status": "affected",
"version": "4.3.4"
},
{
"status": "unaffected",
"version": "4.3.5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "chenhuanlin (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T06:00:10.375Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410875 | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410875"
},
{
"name": "VDB-410875 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410875/cti"
},
{
"name": "CVE-2026-101005 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101005"
},
{
"name": "Submit #922294 | October CMS 4.3.4 (4.x branch, up to commit c1876c7) Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/922294"
},
{
"tags": [
"related"
],
"url": "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
},
{
"tags": [
"related"
],
"url": "https://www.cybersecurity-help.cz/vdb/vulns/149488/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T12:47:16.000Z",
"value": "VulDB entry last update"
}
],
"title": "October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101005",
"datePublished": "2026-09-28T06:00:10.375Z",
"dateReserved": "2026-09-27T10:41:52.940Z",
"dateUpdated": "2026-09-28T12:50:08.482Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100909 (GCVE-0-2026-100909)
Vulnerability from cvelistv5 – Published: 2026-09-28 04:30 – Updated: 2026-09-28 12:48 X_Open Source- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410869 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410869/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100909 | third-party-advisory |
| https://vuldb.com/submit/919993 | third-party-advisory |
| https://github.com/octobercms/october/security/ad… | related |
| https://github.com/0xGenesi/CVE/blob/main/October… | exploit |
| https://github.com/octobercms/october/commit/0e97… | patch |
| https://github.com/octobercms/october/releases/ta… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | OctoberCMS |
Affected:
4.1.0
Affected: 4.1.1 Affected: 4.1.2 Affected: 4.1.3 Affected: 4.1.4 Affected: 4.1.5 Affected: 4.1.6 Affected: 4.1.7 Affected: 4.1.8 Affected: 4.1.9 Affected: 4.1.10 Affected: 4.1.11 Affected: 4.1.12 Affected: 4.1.13 Affected: 4.1.14 Affected: 4.1.15 Affected: 4.1.16 Affected: 4.1.17 Affected: 4.1.18 Affected: 4.1.19 Affected: 4.2.0 Affected: 4.2.1 Affected: 4.2.2 Affected: 4.2.3 Affected: 4.2.4 Affected: 4.2.5 Affected: 4.2.6 Affected: 4.2.7 Affected: 4.2.8 Affected: 4.2.9 Affected: 4.2.10 Affected: 4.2.11 Affected: 4.2.12 Affected: 4.2.13 Affected: 4.2.14 Affected: 4.2.15 Affected: 4.2.16 Affected: 4.2.17 Affected: 4.2.18 Affected: 4.2.19 Affected: 4.2.20 Affected: 4.2.21 Affected: 4.2.22 Affected: 4.2.23 Affected: 4.2.24 Affected: 4.2.25 Affected: 4.3.0 Affected: 4.3.1 Affected: 4.3.2 Affected: 4.3.3 Affected: 4.3.4 Unaffected: 4.3.5 Unaffected: 4.4.0 cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100909",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:48:19.823971Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:48:33.093Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:*"
],
"product": "OctoberCMS",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "4.1.0"
},
{
"status": "affected",
"version": "4.1.1"
},
{
"status": "affected",
"version": "4.1.2"
},
{
"status": "affected",
"version": "4.1.3"
},
{
"status": "affected",
"version": "4.1.4"
},
{
"status": "affected",
"version": "4.1.5"
},
{
"status": "affected",
"version": "4.1.6"
},
{
"status": "affected",
"version": "4.1.7"
},
{
"status": "affected",
"version": "4.1.8"
},
{
"status": "affected",
"version": "4.1.9"
},
{
"status": "affected",
"version": "4.1.10"
},
{
"status": "affected",
"version": "4.1.11"
},
{
"status": "affected",
"version": "4.1.12"
},
{
"status": "affected",
"version": "4.1.13"
},
{
"status": "affected",
"version": "4.1.14"
},
{
"status": "affected",
"version": "4.1.15"
},
{
"status": "affected",
"version": "4.1.16"
},
{
"status": "affected",
"version": "4.1.17"
},
{
"status": "affected",
"version": "4.1.18"
},
{
"status": "affected",
"version": "4.1.19"
},
{
"status": "affected",
"version": "4.2.0"
},
{
"status": "affected",
"version": "4.2.1"
},
{
"status": "affected",
"version": "4.2.2"
},
{
"status": "affected",
"version": "4.2.3"
},
{
"status": "affected",
"version": "4.2.4"
},
{
"status": "affected",
"version": "4.2.5"
},
{
"status": "affected",
"version": "4.2.6"
},
{
"status": "affected",
"version": "4.2.7"
},
{
"status": "affected",
"version": "4.2.8"
},
{
"status": "affected",
"version": "4.2.9"
},
{
"status": "affected",
"version": "4.2.10"
},
{
"status": "affected",
"version": "4.2.11"
},
{
"status": "affected",
"version": "4.2.12"
},
{
"status": "affected",
"version": "4.2.13"
},
{
"status": "affected",
"version": "4.2.14"
},
{
"status": "affected",
"version": "4.2.15"
},
{
"status": "affected",
"version": "4.2.16"
},
{
"status": "affected",
"version": "4.2.17"
},
{
"status": "affected",
"version": "4.2.18"
},
{
"status": "affected",
"version": "4.2.19"
},
{
"status": "affected",
"version": "4.2.20"
},
{
"status": "affected",
"version": "4.2.21"
},
{
"status": "affected",
"version": "4.2.22"
},
{
"status": "affected",
"version": "4.2.23"
},
{
"status": "affected",
"version": "4.2.24"
},
{
"status": "affected",
"version": "4.2.25"
},
{
"status": "affected",
"version": "4.3.0"
},
{
"status": "affected",
"version": "4.3.1"
},
{
"status": "affected",
"version": "4.3.2"
},
{
"status": "affected",
"version": "4.3.3"
},
{
"status": "affected",
"version": "4.3.4"
},
{
"status": "unaffected",
"version": "4.3.5"
},
{
"status": "unaffected",
"version": "4.4.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "chenhuanlin (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T04:30:10.101Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410869 | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410869"
},
{
"name": "VDB-410869 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410869/cti"
},
{
"name": "CVE-2026-100909 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100909"
},
{
"name": "Submit #919993 | octobercms October CMS \u003c= 4.3.4 Path Traversal",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919993"
},
{
"tags": [
"related"
],
"url": "https://github.com/octobercms/october/security/advisories/GHSA-2xmm-m4wv-3fjh"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_Stream_Wrapper_Injection.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/commit/0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T12:24:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100909",
"datePublished": "2026-09-28T04:30:10.101Z",
"dateReserved": "2026-09-27T10:19:16.000Z",
"dateUpdated": "2026-09-28T12:48:33.093Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100901 (GCVE-0-2026-100901)
Vulnerability from cvelistv5 – Published: 2026-09-28 02:45 – Updated: 2026-09-28 12:46- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410851 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410851/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100901 | third-party-advisory |
| https://vuldb.com/submit/919147 | third-party-advisory |
| https://gist.github.com/qianqiusujiu/87a7d7d8bd7f… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| athlon1600 | youtube-downloader |
Affected:
4.0.0
Affected: 4.0.1 cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100901",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:43:15.422685Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:46:00.957Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*"
],
"product": "youtube-downloader",
"vendor": "athlon1600",
"versions": [
{
"status": "affected",
"version": "4.0.0"
},
{
"status": "affected",
"version": "4.0.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "qianqiu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 \u0027better security for public/stream.php\u0027 only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T02:45:10.743Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410851 | athlon1600 youtube-downloader stream.php stream server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410851"
},
{
"name": "VDB-410851 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410851/cti"
},
{
"name": "CVE-2026-100901 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100901"
},
{
"name": "Submit #919147 | Athlon1600 youtube-downloader 6c117f09 (master, 2026-06-02) SSRF (Server-Side Request Forgery)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919147"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/qianqiusujiu/87a7d7d8bd7fb53cf8529e0bafbeafba"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:54:58.000Z",
"value": "VulDB entry last update"
}
],
"title": "athlon1600 youtube-downloader stream.php stream server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100901",
"datePublished": "2026-09-28T02:45:10.743Z",
"dateReserved": "2026-09-27T08:49:53.864Z",
"dateUpdated": "2026-09-28T12:46:00.957Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100900 (GCVE-0-2026-100900)
Vulnerability from cvelistv5 – Published: 2026-09-28 02:30 – Updated: 2026-10-01 14:00- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410850 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410850/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100900 | third-party-advisory |
| https://vuldb.com/submit/919154 | third-party-advisory |
| https://github.com/dddwmr/CVE/blob/main/Server-Si… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| DevaslanPHP | project-management |
Affected:
1.2.1
Affected: 1.2.2 Affected: 1.2.3 Affected: 1.2.4 Affected: v2.0.0-beta1 cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100900",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:59:55.674392Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:00:55.894Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*"
],
"modules": [
"Jira Import"
],
"product": "project-management",
"vendor": "DevaslanPHP",
"versions": [
{
"status": "affected",
"version": "1.2.1"
},
{
"status": "affected",
"version": "1.2.2"
},
{
"status": "affected",
"version": "1.2.3"
},
{
"status": "affected",
"version": "1.2.4"
},
{
"status": "affected",
"version": "v2.0.0-beta1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "dwmm (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T02:30:09.844Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410850 | DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410850"
},
{
"name": "VDB-410850 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410850/cti"
},
{
"name": "CVE-2026-100900 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100900"
},
{
"name": "Submit #919154 | DevaslanPHP project-management \u22641.2.4/2.0.0-beta1 Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919154"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/dddwmr/CVE/blob/main/Server-Side%20Request%20Forgery%20in%20Jira%20Import%20via%20Controllable%20Host%20and%20Missing%20canAccess%20.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:52:54.000Z",
"value": "VulDB entry last update"
}
],
"title": "DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100900",
"datePublished": "2026-09-28T02:30:09.844Z",
"dateReserved": "2026-09-27T08:47:39.646Z",
"dateUpdated": "2026-10-01T14:00:55.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100893 (GCVE-0-2026-100893)
Vulnerability from cvelistv5 – Published: 2026-09-28 00:45 – Updated: 2026-09-28 12:56- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410843 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410843/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100893 | third-party-advisory |
| https://vuldb.com/submit/917632 | third-party-advisory |
| https://is.yuum.me/posts/2026-08-06-ssrf-vulnerab… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Privoce | VoceChat Server |
Affected:
0.5.0
Affected: 0.5.1 Affected: 0.5.2 Affected: 0.5.3 Affected: 0.5.4 Affected: 0.5.5 Affected: 0.5.6 Affected: 0.5.7 Affected: 0.5.8 Affected: 0.5.9 Affected: 0.5.10 Affected: 0.5.11 Affected: 0.5.12 Affected: 0.5.13 Affected: 0.5.14 Affected: 0.5.15 Affected: 0.5.16 Affected: 0.5.17 Affected: 0.5.18 Affected: 0.5.19 Affected: 0.5.20 Affected: 0.5.21 Affected: 0.5.22 Affected: 0.5.23 Affected: 0.5.24 Affected: 0.5.25 Affected: 0.5.26 Affected: 0.5.27 Affected: 0.5.28 Affected: 0.5.29 Affected: 0.5.30 Affected: 0.5.31 Affected: 0.5.32 Affected: 0.5.33 Affected: 0.5.34 Affected: 0.5.35 Affected: 0.5.36 cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100893",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:55:57.650442Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:56:10.518Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*"
],
"modules": [
"open_graphic_parse Endpoint"
],
"product": "VoceChat Server",
"vendor": "Privoce",
"versions": [
{
"status": "affected",
"version": "0.5.0"
},
{
"status": "affected",
"version": "0.5.1"
},
{
"status": "affected",
"version": "0.5.2"
},
{
"status": "affected",
"version": "0.5.3"
},
{
"status": "affected",
"version": "0.5.4"
},
{
"status": "affected",
"version": "0.5.5"
},
{
"status": "affected",
"version": "0.5.6"
},
{
"status": "affected",
"version": "0.5.7"
},
{
"status": "affected",
"version": "0.5.8"
},
{
"status": "affected",
"version": "0.5.9"
},
{
"status": "affected",
"version": "0.5.10"
},
{
"status": "affected",
"version": "0.5.11"
},
{
"status": "affected",
"version": "0.5.12"
},
{
"status": "affected",
"version": "0.5.13"
},
{
"status": "affected",
"version": "0.5.14"
},
{
"status": "affected",
"version": "0.5.15"
},
{
"status": "affected",
"version": "0.5.16"
},
{
"status": "affected",
"version": "0.5.17"
},
{
"status": "affected",
"version": "0.5.18"
},
{
"status": "affected",
"version": "0.5.19"
},
{
"status": "affected",
"version": "0.5.20"
},
{
"status": "affected",
"version": "0.5.21"
},
{
"status": "affected",
"version": "0.5.22"
},
{
"status": "affected",
"version": "0.5.23"
},
{
"status": "affected",
"version": "0.5.24"
},
{
"status": "affected",
"version": "0.5.25"
},
{
"status": "affected",
"version": "0.5.26"
},
{
"status": "affected",
"version": "0.5.27"
},
{
"status": "affected",
"version": "0.5.28"
},
{
"status": "affected",
"version": "0.5.29"
},
{
"status": "affected",
"version": "0.5.30"
},
{
"status": "affected",
"version": "0.5.31"
},
{
"status": "affected",
"version": "0.5.32"
},
{
"status": "affected",
"version": "0.5.33"
},
{
"status": "affected",
"version": "0.5.34"
},
{
"status": "affected",
"version": "0.5.35"
},
{
"status": "affected",
"version": "0.5.36"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "yumeu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T00:45:15.919Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410843 | Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410843"
},
{
"name": "VDB-410843 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410843/cti"
},
{
"name": "CVE-2026-100893 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100893"
},
{
"name": "Submit #917632 | Privoce, Inc VoceChat Server \u003c= 0.5.20 Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/917632"
},
{
"tags": [
"exploit"
],
"url": "https://is.yuum.me/posts/2026-08-06-ssrf-vulnerability-in-vocechat-server-v0520/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:18:47.000Z",
"value": "VulDB entry last update"
}
],
"title": "Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100893",
"datePublished": "2026-09-28T00:45:15.919Z",
"dateReserved": "2026-09-27T08:13:43.009Z",
"dateUpdated": "2026-09-28T12:56:10.518Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100863 (GCVE-0-2026-100863)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:24- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100863",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:23:50.708780Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:24:03.334Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.91",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.91",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-15T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client; because the workflow DSL supports \"imageInput\": \"$userInput.body.imageUrl\", a webhook or API caller can choose the fetch target when a workflow author uses that expression, allowing requests to loopback, RFC1918, and cloud metadata endpoints. Second, _is_public_address unwrapped only IPv4-mapped IPv6 addresses, so IPv6 transition forms \u2014 the NAT64 well-known prefix 64:ff9b::/96, deprecated IPv4-compatible ::x.x.x.x addresses, and 6to4 (2002::/16, classified as globally routable by Python 3.11.0 through 3.11.9) \u2014 could carry loopback, RFC1918, link-local, or cloud-metadata IPv4 destinations past both the initial URL validation and the dial-time IP pin. Version 0.0.91 routes the image loader through guard_http_url and the guarded client, evaluates NAT64 and IPv4-compatible addresses by their embedded IPv4 address, and refuses 64:ff9b:1::/48, 6to4, and Teredo (2001::/32) outright."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:52.561Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-6rph-qqcv-jqh4)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-6rph-qqcv-jqh4"
},
{
"name": "VulnCheck Advisory: Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.91-ssrf-via-image-fetching-and-ipv6-validation"
}
],
"title": "Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100863",
"datePublished": "2026-09-27T01:28:52.561Z",
"dateReserved": "2026-09-27T00:20:54.407Z",
"dateUpdated": "2026-09-30T15:24:03.334Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100861 (GCVE-0-2026-100861)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-28 13:38- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100861",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:38:17.642917Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:38:46.572Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.105",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.105",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "fatihkaratash"
},
{
"lang": "en",
"type": "finder",
"value": "mbakgun"
}
],
"datePublic": "2026-09-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:51.256Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xchj-mw74-2232)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
},
{
"name": "VulnCheck Advisory: heym before 0.0.105 SSRF via credential-controlled base URLs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.105-ssrf-via-credential-controlled-base-urls"
}
],
"title": "heym before 0.0.105 SSRF via credential-controlled base URLs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100861",
"datePublished": "2026-09-27T01:28:51.256Z",
"dateReserved": "2026-09-27T00:20:03.854Z",
"dateUpdated": "2026-09-28T13:38:46.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100859 (GCVE-0-2026-100859)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:23- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100859",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:22:55.534844Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:23:06.521Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.106",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.106",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "roonakyadav"
},
{
"lang": "en",
"type": "finder",
"value": "mbakgun"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner\u0027s secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:49.880Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-39qx-wp7x-69rq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-39qx-wp7x-69rq"
},
{
"name": "VulnCheck Advisory: Heym before 0.0.106 Credential Exfiltration via URL Override",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.106-credential-exfiltration-via-url-override"
}
],
"title": "Heym before 0.0.106 Credential Exfiltration via URL Override",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100859",
"datePublished": "2026-09-27T01:28:49.880Z",
"dateReserved": "2026-09-27T00:20:03.854Z",
"dateUpdated": "2026-09-30T15:23:06.521Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100858 (GCVE-0-2026-100858)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:41- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100858",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:41:43.926464Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:41:51.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-39j3-6x3x-8rcr"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.109",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.109",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "unbengable12"
},
{
"lang": "en",
"type": "finder",
"value": "mbakgun"
}
],
"datePublic": "2026-09-12T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty. Any registered user can create a credential pointing at an internal address and execute a workflow, causing the backend to reach loopback, private, link-local, or cloud-metadata endpoints and return the full response body in the node output (non-blind SSRF)."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:49.185Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-39j3-6x3x-8rcr)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-39j3-6x3x-8rcr"
},
{
"name": "VulnCheck Advisory: heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.109-server-side-request-forgery-via-workflow-nodes"
}
],
"title": "heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100858",
"datePublished": "2026-09-27T01:28:49.185Z",
"dateReserved": "2026-09-27T00:20:03.854Z",
"dateUpdated": "2026-09-30T15:41:51.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100850 (GCVE-0-2026-100850)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:54- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/AzuraCast/AzuraCast/security/a… | vendor-advisory |
| https://www.vulncheck.com/advisories/azuracast-be… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100850",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:54:30.806523Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:54:40.858Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-rrjx-wrhf-8v47"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AzuraCast",
"vendor": "AzuraCast",
"versions": [
{
"lessThan": "0.23.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.23.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.23.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Alpastx"
}
],
"datePublic": "2026-08-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local HTTP endpoint. When AutoDJ builds the queue, the backend passes the user-supplied URL directly to file_get_contents() with no scheme allowlist and no private/loopback/metadata IP policy (PHP allow_url_fopen is enabled by default, including in the Docker image). Lines from the fetched resource are parsed as M3U/PLS entries, stored in StationQueue.autodj_custom_uri, and returned by GET /api/station/{station_id}/queue to any user with the Broadcasting permission, disclosing host files readable by the web container (for example /etc/passwd or the application .env) and the bodies of non-blind internal HTTP requests. No patched version was available at the time of publication."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:43.673Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-rrjx-wrhf-8v47)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-rrjx-wrhf-8v47"
},
{
"name": "VulnCheck Advisory: AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/azuracast-before-0.23.8-ssrf-and-local-file-read-via-remote-playlist"
}
],
"title": "AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100850",
"datePublished": "2026-09-27T01:28:43.673Z",
"dateReserved": "2026-09-27T00:18:40.972Z",
"dateUpdated": "2026-09-30T15:54:40.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
No mitigation information available for this CWE.
CAPEC-664: Server Side Request Forgery
An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server’s internal network, or to external third parties. If successful, the adversary’s request will be made with the server’s privilege level, bypassing its authentication controls. This ultimately allows the adversary to access sensitive data, execute commands on the server’s network, and make external requests with the stolen identity of the server. Server Side Request Forgery attacks differ from Cross Site Request Forgery attacks in that they target the server itself, whereas CSRF attacks exploit an insecure user authentication mechanism to perform unauthorized actions on the user's behalf.