CWE-918
AllowedServer-Side Request Forgery (SSRF)
Abstraction: Base · Status: Incomplete
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
6162 vulnerabilities reference this CWE, most recent first.
CVE-2026-101059 (GCVE-0-2026-101059)
Vulnerability from cvelistv5 – Published: 2026-09-27 17:02 – Updated: 2026-09-28 14:02- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/universal-tool-calling-protoco… | vendor-advisory |
| https://www.vulncheck.com/advisories/utcp-http-be… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| universal-tool-calling-protocol | python-utcp |
Affected:
0 , < 1.1.4
(semver)
Unaffected: 1.1.4 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101059",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:00:16.325429Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T14:02:40.274Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8cp3-qxj6-px34"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/utcp-http",
"product": "python-utcp",
"vendor": "universal-tool-calling-protocol",
"versions": [
{
"lessThan": "1.1.4",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.4",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "EQSTLab"
},
{
"lang": "en",
"type": "analyst",
"value": "232-323"
}
],
"datePublic": "2026-06-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim\u0027s client_id and client_secret to the attacker-supplied token endpoint without URL validation."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T17:02:40.181Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8cp3-qxj6-px34)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8cp3-qxj6-px34"
},
{
"name": "VulnCheck Advisory: utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/utcp-http-before-1.1.4-oauth2-tokenurl-trust-boundary-bypass"
}
],
"title": "utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-101059",
"datePublished": "2026-09-27T17:02:40.181Z",
"dateReserved": "2026-09-27T16:38:56.428Z",
"dateUpdated": "2026-09-28T14:02:40.274Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101058 (GCVE-0-2026-101058)
Vulnerability from cvelistv5 – Published: 2026-09-27 17:02 – Updated: 2026-09-30 22:06- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/universal-tool-calling-protoco… | vendor-advisory |
| https://www.vulncheck.com/advisories/python-utcp-… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| universal-tool-calling-protocol | python-utcp |
Affected:
0 , < 1.1.12
(semver)
Unaffected: 1.1.12 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101058",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T22:06:18.895295Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T22:06:29.482Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/utcp-http",
"product": "python-utcp",
"vendor": "universal-tool-calling-protocol",
"versions": [
{
"lessThan": "1.1.12",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.12",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "EQSTLab"
},
{
"lang": "en",
"type": "analyst",
"value": "232-323"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent\u0027s own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T17:02:39.400Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8vxx-v7r9-948g)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8vxx-v7r9-948g"
},
{
"name": "VulnCheck Advisory: python-utcp before 1.1.12 SSRF via Remote HTTP Manual",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/python-utcp-before-1.1.12-ssrf-via-remote-http-manual"
}
],
"title": "python-utcp before 1.1.12 SSRF via Remote HTTP Manual",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-101058",
"datePublished": "2026-09-27T17:02:39.400Z",
"dateReserved": "2026-09-27T16:38:56.428Z",
"dateUpdated": "2026-09-30T22:06:29.482Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101005 (GCVE-0-2026-101005)
Vulnerability from cvelistv5 – Published: 2026-09-28 06:00 – Updated: 2026-09-28 12:50- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410875 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410875/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101005 | third-party-advisory |
| https://vuldb.com/submit/922294 | third-party-advisory |
| https://github.com/octobercms/october/security/ad… | related |
| https://github.com/0xGenesi/CVE/blob/main/October… | exploit |
| https://github.com/octobercms/october/releases/ta… | patch |
| https://www.cybersecurity-help.cz/vdb/vulns/149488/ | related |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | October CMS |
Affected:
4.3.0
Affected: 4.3.1 Affected: 4.3.2 Affected: 4.3.3 Affected: 4.3.4 Unaffected: 4.3.5 cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101005",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:49:57.801754Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:50:08.482Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:*"
],
"modules": [
"SSRF Protection"
],
"product": "October CMS",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "4.3.0"
},
{
"status": "affected",
"version": "4.3.1"
},
{
"status": "affected",
"version": "4.3.2"
},
{
"status": "affected",
"version": "4.3.3"
},
{
"status": "affected",
"version": "4.3.4"
},
{
"status": "unaffected",
"version": "4.3.5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "chenhuanlin (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T06:00:10.375Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410875 | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410875"
},
{
"name": "VDB-410875 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410875/cti"
},
{
"name": "CVE-2026-101005 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101005"
},
{
"name": "Submit #922294 | October CMS 4.3.4 (4.x branch, up to commit c1876c7) Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/922294"
},
{
"tags": [
"related"
],
"url": "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
},
{
"tags": [
"related"
],
"url": "https://www.cybersecurity-help.cz/vdb/vulns/149488/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T12:47:16.000Z",
"value": "VulDB entry last update"
}
],
"title": "October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101005",
"datePublished": "2026-09-28T06:00:10.375Z",
"dateReserved": "2026-09-27T10:41:52.940Z",
"dateUpdated": "2026-09-28T12:50:08.482Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100909 (GCVE-0-2026-100909)
Vulnerability from cvelistv5 – Published: 2026-09-28 04:30 – Updated: 2026-09-28 12:48 X_Open Source- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410869 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410869/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100909 | third-party-advisory |
| https://vuldb.com/submit/919993 | third-party-advisory |
| https://github.com/octobercms/october/security/ad… | related |
| https://github.com/0xGenesi/CVE/blob/main/October… | exploit |
| https://github.com/octobercms/october/commit/0e97… | patch |
| https://github.com/octobercms/october/releases/ta… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | OctoberCMS |
Affected:
4.1.0
Affected: 4.1.1 Affected: 4.1.2 Affected: 4.1.3 Affected: 4.1.4 Affected: 4.1.5 Affected: 4.1.6 Affected: 4.1.7 Affected: 4.1.8 Affected: 4.1.9 Affected: 4.1.10 Affected: 4.1.11 Affected: 4.1.12 Affected: 4.1.13 Affected: 4.1.14 Affected: 4.1.15 Affected: 4.1.16 Affected: 4.1.17 Affected: 4.1.18 Affected: 4.1.19 Affected: 4.2.0 Affected: 4.2.1 Affected: 4.2.2 Affected: 4.2.3 Affected: 4.2.4 Affected: 4.2.5 Affected: 4.2.6 Affected: 4.2.7 Affected: 4.2.8 Affected: 4.2.9 Affected: 4.2.10 Affected: 4.2.11 Affected: 4.2.12 Affected: 4.2.13 Affected: 4.2.14 Affected: 4.2.15 Affected: 4.2.16 Affected: 4.2.17 Affected: 4.2.18 Affected: 4.2.19 Affected: 4.2.20 Affected: 4.2.21 Affected: 4.2.22 Affected: 4.2.23 Affected: 4.2.24 Affected: 4.2.25 Affected: 4.3.0 Affected: 4.3.1 Affected: 4.3.2 Affected: 4.3.3 Affected: 4.3.4 Unaffected: 4.3.5 Unaffected: 4.4.0 cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100909",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:48:19.823971Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:48:33.093Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:*"
],
"product": "OctoberCMS",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "4.1.0"
},
{
"status": "affected",
"version": "4.1.1"
},
{
"status": "affected",
"version": "4.1.2"
},
{
"status": "affected",
"version": "4.1.3"
},
{
"status": "affected",
"version": "4.1.4"
},
{
"status": "affected",
"version": "4.1.5"
},
{
"status": "affected",
"version": "4.1.6"
},
{
"status": "affected",
"version": "4.1.7"
},
{
"status": "affected",
"version": "4.1.8"
},
{
"status": "affected",
"version": "4.1.9"
},
{
"status": "affected",
"version": "4.1.10"
},
{
"status": "affected",
"version": "4.1.11"
},
{
"status": "affected",
"version": "4.1.12"
},
{
"status": "affected",
"version": "4.1.13"
},
{
"status": "affected",
"version": "4.1.14"
},
{
"status": "affected",
"version": "4.1.15"
},
{
"status": "affected",
"version": "4.1.16"
},
{
"status": "affected",
"version": "4.1.17"
},
{
"status": "affected",
"version": "4.1.18"
},
{
"status": "affected",
"version": "4.1.19"
},
{
"status": "affected",
"version": "4.2.0"
},
{
"status": "affected",
"version": "4.2.1"
},
{
"status": "affected",
"version": "4.2.2"
},
{
"status": "affected",
"version": "4.2.3"
},
{
"status": "affected",
"version": "4.2.4"
},
{
"status": "affected",
"version": "4.2.5"
},
{
"status": "affected",
"version": "4.2.6"
},
{
"status": "affected",
"version": "4.2.7"
},
{
"status": "affected",
"version": "4.2.8"
},
{
"status": "affected",
"version": "4.2.9"
},
{
"status": "affected",
"version": "4.2.10"
},
{
"status": "affected",
"version": "4.2.11"
},
{
"status": "affected",
"version": "4.2.12"
},
{
"status": "affected",
"version": "4.2.13"
},
{
"status": "affected",
"version": "4.2.14"
},
{
"status": "affected",
"version": "4.2.15"
},
{
"status": "affected",
"version": "4.2.16"
},
{
"status": "affected",
"version": "4.2.17"
},
{
"status": "affected",
"version": "4.2.18"
},
{
"status": "affected",
"version": "4.2.19"
},
{
"status": "affected",
"version": "4.2.20"
},
{
"status": "affected",
"version": "4.2.21"
},
{
"status": "affected",
"version": "4.2.22"
},
{
"status": "affected",
"version": "4.2.23"
},
{
"status": "affected",
"version": "4.2.24"
},
{
"status": "affected",
"version": "4.2.25"
},
{
"status": "affected",
"version": "4.3.0"
},
{
"status": "affected",
"version": "4.3.1"
},
{
"status": "affected",
"version": "4.3.2"
},
{
"status": "affected",
"version": "4.3.3"
},
{
"status": "affected",
"version": "4.3.4"
},
{
"status": "unaffected",
"version": "4.3.5"
},
{
"status": "unaffected",
"version": "4.4.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "chenhuanlin (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T04:30:10.101Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410869 | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410869"
},
{
"name": "VDB-410869 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410869/cti"
},
{
"name": "CVE-2026-100909 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100909"
},
{
"name": "Submit #919993 | octobercms October CMS \u003c= 4.3.4 Path Traversal",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919993"
},
{
"tags": [
"related"
],
"url": "https://github.com/octobercms/october/security/advisories/GHSA-2xmm-m4wv-3fjh"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_Stream_Wrapper_Injection.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/commit/0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58"
},
{
"tags": [
"patch"
],
"url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T12:24:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100909",
"datePublished": "2026-09-28T04:30:10.101Z",
"dateReserved": "2026-09-27T10:19:16.000Z",
"dateUpdated": "2026-09-28T12:48:33.093Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100901 (GCVE-0-2026-100901)
Vulnerability from cvelistv5 – Published: 2026-09-28 02:45 – Updated: 2026-09-28 12:46- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410851 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410851/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100901 | third-party-advisory |
| https://vuldb.com/submit/919147 | third-party-advisory |
| https://gist.github.com/qianqiusujiu/87a7d7d8bd7f… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| athlon1600 | youtube-downloader |
Affected:
4.0.0
Affected: 4.0.1 cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100901",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:43:15.422685Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:46:00.957Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*"
],
"product": "youtube-downloader",
"vendor": "athlon1600",
"versions": [
{
"status": "affected",
"version": "4.0.0"
},
{
"status": "affected",
"version": "4.0.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "qianqiu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 \u0027better security for public/stream.php\u0027 only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T02:45:10.743Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410851 | athlon1600 youtube-downloader stream.php stream server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410851"
},
{
"name": "VDB-410851 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410851/cti"
},
{
"name": "CVE-2026-100901 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100901"
},
{
"name": "Submit #919147 | Athlon1600 youtube-downloader 6c117f09 (master, 2026-06-02) SSRF (Server-Side Request Forgery)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919147"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/qianqiusujiu/87a7d7d8bd7fb53cf8529e0bafbeafba"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:54:58.000Z",
"value": "VulDB entry last update"
}
],
"title": "athlon1600 youtube-downloader stream.php stream server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100901",
"datePublished": "2026-09-28T02:45:10.743Z",
"dateReserved": "2026-09-27T08:49:53.864Z",
"dateUpdated": "2026-09-28T12:46:00.957Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100900 (GCVE-0-2026-100900)
Vulnerability from cvelistv5 – Published: 2026-09-28 02:30 – Updated: 2026-10-01 14:00- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410850 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410850/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100900 | third-party-advisory |
| https://vuldb.com/submit/919154 | third-party-advisory |
| https://github.com/dddwmr/CVE/blob/main/Server-Si… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| DevaslanPHP | project-management |
Affected:
1.2.1
Affected: 1.2.2 Affected: 1.2.3 Affected: 1.2.4 Affected: v2.0.0-beta1 cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100900",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:59:55.674392Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:00:55.894Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*"
],
"modules": [
"Jira Import"
],
"product": "project-management",
"vendor": "DevaslanPHP",
"versions": [
{
"status": "affected",
"version": "1.2.1"
},
{
"status": "affected",
"version": "1.2.2"
},
{
"status": "affected",
"version": "1.2.3"
},
{
"status": "affected",
"version": "1.2.4"
},
{
"status": "affected",
"version": "v2.0.0-beta1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "dwmm (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T02:30:09.844Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410850 | DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410850"
},
{
"name": "VDB-410850 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410850/cti"
},
{
"name": "CVE-2026-100900 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100900"
},
{
"name": "Submit #919154 | DevaslanPHP project-management \u22641.2.4/2.0.0-beta1 Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/919154"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/dddwmr/CVE/blob/main/Server-Side%20Request%20Forgery%20in%20Jira%20Import%20via%20Controllable%20Host%20and%20Missing%20canAccess%20.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:52:54.000Z",
"value": "VulDB entry last update"
}
],
"title": "DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100900",
"datePublished": "2026-09-28T02:30:09.844Z",
"dateReserved": "2026-09-27T08:47:39.646Z",
"dateUpdated": "2026-10-01T14:00:55.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100893 (GCVE-0-2026-100893)
Vulnerability from cvelistv5 – Published: 2026-09-28 00:45 – Updated: 2026-09-28 12:56- CWE-918 - Server-Side Request Forgery
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410843 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410843/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100893 | third-party-advisory |
| https://vuldb.com/submit/917632 | third-party-advisory |
| https://is.yuum.me/posts/2026-08-06-ssrf-vulnerab… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Privoce | VoceChat Server |
Affected:
0.5.0
Affected: 0.5.1 Affected: 0.5.2 Affected: 0.5.3 Affected: 0.5.4 Affected: 0.5.5 Affected: 0.5.6 Affected: 0.5.7 Affected: 0.5.8 Affected: 0.5.9 Affected: 0.5.10 Affected: 0.5.11 Affected: 0.5.12 Affected: 0.5.13 Affected: 0.5.14 Affected: 0.5.15 Affected: 0.5.16 Affected: 0.5.17 Affected: 0.5.18 Affected: 0.5.19 Affected: 0.5.20 Affected: 0.5.21 Affected: 0.5.22 Affected: 0.5.23 Affected: 0.5.24 Affected: 0.5.25 Affected: 0.5.26 Affected: 0.5.27 Affected: 0.5.28 Affected: 0.5.29 Affected: 0.5.30 Affected: 0.5.31 Affected: 0.5.32 Affected: 0.5.33 Affected: 0.5.34 Affected: 0.5.35 Affected: 0.5.36 cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100893",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:55:57.650442Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:56:10.518Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*"
],
"modules": [
"open_graphic_parse Endpoint"
],
"product": "VoceChat Server",
"vendor": "Privoce",
"versions": [
{
"status": "affected",
"version": "0.5.0"
},
{
"status": "affected",
"version": "0.5.1"
},
{
"status": "affected",
"version": "0.5.2"
},
{
"status": "affected",
"version": "0.5.3"
},
{
"status": "affected",
"version": "0.5.4"
},
{
"status": "affected",
"version": "0.5.5"
},
{
"status": "affected",
"version": "0.5.6"
},
{
"status": "affected",
"version": "0.5.7"
},
{
"status": "affected",
"version": "0.5.8"
},
{
"status": "affected",
"version": "0.5.9"
},
{
"status": "affected",
"version": "0.5.10"
},
{
"status": "affected",
"version": "0.5.11"
},
{
"status": "affected",
"version": "0.5.12"
},
{
"status": "affected",
"version": "0.5.13"
},
{
"status": "affected",
"version": "0.5.14"
},
{
"status": "affected",
"version": "0.5.15"
},
{
"status": "affected",
"version": "0.5.16"
},
{
"status": "affected",
"version": "0.5.17"
},
{
"status": "affected",
"version": "0.5.18"
},
{
"status": "affected",
"version": "0.5.19"
},
{
"status": "affected",
"version": "0.5.20"
},
{
"status": "affected",
"version": "0.5.21"
},
{
"status": "affected",
"version": "0.5.22"
},
{
"status": "affected",
"version": "0.5.23"
},
{
"status": "affected",
"version": "0.5.24"
},
{
"status": "affected",
"version": "0.5.25"
},
{
"status": "affected",
"version": "0.5.26"
},
{
"status": "affected",
"version": "0.5.27"
},
{
"status": "affected",
"version": "0.5.28"
},
{
"status": "affected",
"version": "0.5.29"
},
{
"status": "affected",
"version": "0.5.30"
},
{
"status": "affected",
"version": "0.5.31"
},
{
"status": "affected",
"version": "0.5.32"
},
{
"status": "affected",
"version": "0.5.33"
},
{
"status": "affected",
"version": "0.5.34"
},
{
"status": "affected",
"version": "0.5.35"
},
{
"status": "affected",
"version": "0.5.36"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "yumeu (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T00:45:15.919Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410843 | Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410843"
},
{
"name": "VDB-410843 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410843/cti"
},
{
"name": "CVE-2026-100893 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100893"
},
{
"name": "Submit #917632 | Privoce, Inc VoceChat Server \u003c= 0.5.20 Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/917632"
},
{
"tags": [
"exploit"
],
"url": "https://is.yuum.me/posts/2026-08-06-ssrf-vulnerability-in-vocechat-server-v0520/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:18:47.000Z",
"value": "VulDB entry last update"
}
],
"title": "Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100893",
"datePublished": "2026-09-28T00:45:15.919Z",
"dateReserved": "2026-09-27T08:13:43.009Z",
"dateUpdated": "2026-09-28T12:56:10.518Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100863 (GCVE-0-2026-100863)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:24- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100863",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:23:50.708780Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:24:03.334Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.91",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.91",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-15T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client; because the workflow DSL supports \"imageInput\": \"$userInput.body.imageUrl\", a webhook or API caller can choose the fetch target when a workflow author uses that expression, allowing requests to loopback, RFC1918, and cloud metadata endpoints. Second, _is_public_address unwrapped only IPv4-mapped IPv6 addresses, so IPv6 transition forms \u2014 the NAT64 well-known prefix 64:ff9b::/96, deprecated IPv4-compatible ::x.x.x.x addresses, and 6to4 (2002::/16, classified as globally routable by Python 3.11.0 through 3.11.9) \u2014 could carry loopback, RFC1918, link-local, or cloud-metadata IPv4 destinations past both the initial URL validation and the dial-time IP pin. Version 0.0.91 routes the image loader through guard_http_url and the guarded client, evaluates NAT64 and IPv4-compatible addresses by their embedded IPv4 address, and refuses 64:ff9b:1::/48, 6to4, and Teredo (2001::/32) outright."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:52.561Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-6rph-qqcv-jqh4)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-6rph-qqcv-jqh4"
},
{
"name": "VulnCheck Advisory: Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.91-ssrf-via-image-fetching-and-ipv6-validation"
}
],
"title": "Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100863",
"datePublished": "2026-09-27T01:28:52.561Z",
"dateReserved": "2026-09-27T00:20:54.407Z",
"dateUpdated": "2026-09-30T15:24:03.334Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100861 (GCVE-0-2026-100861)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-28 13:38- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100861",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:38:17.642917Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:38:46.572Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.105",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.105",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "fatihkaratash"
},
{
"lang": "en",
"type": "finder",
"value": "mbakgun"
}
],
"datePublic": "2026-09-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:51.256Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xchj-mw74-2232)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
},
{
"name": "VulnCheck Advisory: heym before 0.0.105 SSRF via credential-controlled base URLs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.105-ssrf-via-credential-controlled-base-urls"
}
],
"title": "heym before 0.0.105 SSRF via credential-controlled base URLs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100861",
"datePublished": "2026-09-27T01:28:51.256Z",
"dateReserved": "2026-09-27T00:20:03.854Z",
"dateUpdated": "2026-09-28T13:38:46.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100859 (GCVE-0-2026-100859)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:23- CWE-918 - Server-Side Request Forgery (SSRF)
| URL | Tags |
|---|---|
| https://github.com/heymrun/heym/security/advisori… | vendor-advisory |
| https://www.vulncheck.com/advisories/heym-before-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100859",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:22:55.534844Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:23:06.521Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "heym",
"vendor": "heymrun",
"versions": [
{
"lessThan": "0.0.106",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.0.106",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "roonakyadav"
},
{
"lang": "en",
"type": "finder",
"value": "mbakgun"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner\u0027s secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:49.880Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-39qx-wp7x-69rq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/heymrun/heym/security/advisories/GHSA-39qx-wp7x-69rq"
},
{
"name": "VulnCheck Advisory: Heym before 0.0.106 Credential Exfiltration via URL Override",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/heym-before-0.0.106-credential-exfiltration-via-url-override"
}
],
"title": "Heym before 0.0.106 Credential Exfiltration via URL Override",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100859",
"datePublished": "2026-09-27T01:28:49.880Z",
"dateReserved": "2026-09-27T00:20:03.854Z",
"dateUpdated": "2026-09-30T15:23:06.521Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
No mitigation information available for this CWE.
CAPEC-664: Server Side Request Forgery
An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server’s internal network, or to external third parties. If successful, the adversary’s request will be made with the server’s privilege level, bypassing its authentication controls. This ultimately allows the adversary to access sensitive data, execute commands on the server’s network, and make external requests with the stolen identity of the server. Server Side Request Forgery attacks differ from Cross Site Request Forgery attacks in that they target the server itself, whereas CSRF attacks exploit an insecure user authentication mechanism to perform unauthorized actions on the user's behalf.