Common Weakness Enumeration

CWE-918

Allowed

Server-Side Request Forgery (SSRF)

Abstraction: Base · Status: Incomplete

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

6162 vulnerabilities reference this CWE, most recent first.

CVE-2026-101059 (GCVE-0-2026-101059)

Vulnerability from cvelistv5 – Published: 2026-09-27 17:02 – Updated: 2026-09-28 14:02
VLAI
Title
utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
Summary
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's client_id and client_secret to the attacker-supplied token endpoint without URL validation.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 14:00 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
universal-tool-calling-protocol python-utcp Affected: 0 , < 1.1.4 (semver)
Unaffected: 1.1.4 (semver)
Create a notification for this product.
Date Public
2026-06-14 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-101059",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T14:00:16.325429Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T14:02:40.274Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8cp3-qxj6-px34"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:pypi/utcp-http",
          "product": "python-utcp",
          "vendor": "universal-tool-calling-protocol",
          "versions": [
            {
              "lessThan": "1.1.4",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "1.1.4",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "EQSTLab"
        },
        {
          "lang": "en",
          "type": "analyst",
          "value": "232-323"
        }
      ],
      "datePublic": "2026-06-14T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim\u0027s client_id and client_secret to the attacker-supplied token endpoint without URL validation."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T17:02:40.181Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-8cp3-qxj6-px34)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8cp3-qxj6-px34"
        },
        {
          "name": "VulnCheck Advisory: utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/utcp-http-before-1.1.4-oauth2-tokenurl-trust-boundary-bypass"
        }
      ],
      "title": "utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-101059",
    "datePublished": "2026-09-27T17:02:40.181Z",
    "dateReserved": "2026-09-27T16:38:56.428Z",
    "dateUpdated": "2026-09-28T14:02:40.274Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-101058 (GCVE-0-2026-101058)

Vulnerability from cvelistv5 – Published: 2026-09-27 17:02 – Updated: 2026-09-30 22:06
VLAI
Title
python-utcp before 1.1.12 SSRF via Remote HTTP Manual
Summary
python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 22:06 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
universal-tool-calling-protocol python-utcp Affected: 0 , < 1.1.12 (semver)
Unaffected: 1.1.12 (semver)
Create a notification for this product.
Date Public
2026-09-05 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-101058",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T22:06:18.895295Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T22:06:29.482Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:pypi/utcp-http",
          "product": "python-utcp",
          "vendor": "universal-tool-calling-protocol",
          "versions": [
            {
              "lessThan": "1.1.12",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "1.1.12",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "EQSTLab"
        },
        {
          "lang": "en",
          "type": "analyst",
          "value": "232-323"
        }
      ],
      "datePublic": "2026-09-05T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent\u0027s own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "LOW",
            "userInteraction": "PASSIVE",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T17:02:39.400Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-8vxx-v7r9-948g)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8vxx-v7r9-948g"
        },
        {
          "name": "VulnCheck Advisory: python-utcp before 1.1.12 SSRF via Remote HTTP Manual",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/python-utcp-before-1.1.12-ssrf-via-remote-http-manual"
        }
      ],
      "title": "python-utcp before 1.1.12 SSRF via Remote HTTP Manual",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-101058",
    "datePublished": "2026-09-27T17:02:39.400Z",
    "dateReserved": "2026-09-27T16:38:56.428Z",
    "dateUpdated": "2026-09-30T22:06:29.482Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-101005 (GCVE-0-2026-101005)

Vulnerability from cvelistv5 – Published: 2026-09-28 06:00 – Updated: 2026-09-28 12:50
VLAI
Title
October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery
Summary
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 12:49 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
Impacted products
Vendor Product Version
n/a October CMS Affected: 4.3.0
Affected: 4.3.1
Affected: 4.3.2
Affected: 4.3.3
Affected: 4.3.4
Unaffected: 4.3.5
    cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-101005",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T12:49:57.801754Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T12:50:08.482Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:october_cms:october_cms:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "SSRF Protection"
          ],
          "product": "October CMS",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "4.3.0"
            },
            {
              "status": "affected",
              "version": "4.3.1"
            },
            {
              "status": "affected",
              "version": "4.3.2"
            },
            {
              "status": "affected",
              "version": "4.3.3"
            },
            {
              "status": "affected",
              "version": "4.3.4"
            },
            {
              "status": "unaffected",
              "version": "4.3.5"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "chenhuanlin (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T06:00:10.375Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-410875 | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/410875"
        },
        {
          "name": "VDB-410875 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/410875/cti"
        },
        {
          "name": "CVE-2026-101005 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-101005"
        },
        {
          "name": "Submit #922294 | October CMS 4.3.4 (4.x branch, up to commit c1876c7) Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/922294"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://www.cybersecurity-help.cz/vdb/vulns/149488/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-27T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-27T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-27T12:47:16.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-101005",
    "datePublished": "2026-09-28T06:00:10.375Z",
    "dateReserved": "2026-09-27T10:41:52.940Z",
    "dateUpdated": "2026-09-28T12:50:08.482Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100909 (GCVE-0-2026-100909)

Vulnerability from cvelistv5 – Published: 2026-09-28 04:30 – Updated: 2026-09-28 12:48 X_Open Source
VLAI
Title
OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery
Summary
A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 12:48 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
Impacted products
Vendor Product Version
n/a OctoberCMS Affected: 4.1.0
Affected: 4.1.1
Affected: 4.1.2
Affected: 4.1.3
Affected: 4.1.4
Affected: 4.1.5
Affected: 4.1.6
Affected: 4.1.7
Affected: 4.1.8
Affected: 4.1.9
Affected: 4.1.10
Affected: 4.1.11
Affected: 4.1.12
Affected: 4.1.13
Affected: 4.1.14
Affected: 4.1.15
Affected: 4.1.16
Affected: 4.1.17
Affected: 4.1.18
Affected: 4.1.19
Affected: 4.2.0
Affected: 4.2.1
Affected: 4.2.2
Affected: 4.2.3
Affected: 4.2.4
Affected: 4.2.5
Affected: 4.2.6
Affected: 4.2.7
Affected: 4.2.8
Affected: 4.2.9
Affected: 4.2.10
Affected: 4.2.11
Affected: 4.2.12
Affected: 4.2.13
Affected: 4.2.14
Affected: 4.2.15
Affected: 4.2.16
Affected: 4.2.17
Affected: 4.2.18
Affected: 4.2.19
Affected: 4.2.20
Affected: 4.2.21
Affected: 4.2.22
Affected: 4.2.23
Affected: 4.2.24
Affected: 4.2.25
Affected: 4.3.0
Affected: 4.3.1
Affected: 4.3.2
Affected: 4.3.3
Affected: 4.3.4
Unaffected: 4.3.5
Unaffected: 4.4.0
    cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100909",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T12:48:19.823971Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T12:48:33.093Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:*"
          ],
          "product": "OctoberCMS",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.0"
            },
            {
              "status": "affected",
              "version": "4.1.1"
            },
            {
              "status": "affected",
              "version": "4.1.2"
            },
            {
              "status": "affected",
              "version": "4.1.3"
            },
            {
              "status": "affected",
              "version": "4.1.4"
            },
            {
              "status": "affected",
              "version": "4.1.5"
            },
            {
              "status": "affected",
              "version": "4.1.6"
            },
            {
              "status": "affected",
              "version": "4.1.7"
            },
            {
              "status": "affected",
              "version": "4.1.8"
            },
            {
              "status": "affected",
              "version": "4.1.9"
            },
            {
              "status": "affected",
              "version": "4.1.10"
            },
            {
              "status": "affected",
              "version": "4.1.11"
            },
            {
              "status": "affected",
              "version": "4.1.12"
            },
            {
              "status": "affected",
              "version": "4.1.13"
            },
            {
              "status": "affected",
              "version": "4.1.14"
            },
            {
              "status": "affected",
              "version": "4.1.15"
            },
            {
              "status": "affected",
              "version": "4.1.16"
            },
            {
              "status": "affected",
              "version": "4.1.17"
            },
            {
              "status": "affected",
              "version": "4.1.18"
            },
            {
              "status": "affected",
              "version": "4.1.19"
            },
            {
              "status": "affected",
              "version": "4.2.0"
            },
            {
              "status": "affected",
              "version": "4.2.1"
            },
            {
              "status": "affected",
              "version": "4.2.2"
            },
            {
              "status": "affected",
              "version": "4.2.3"
            },
            {
              "status": "affected",
              "version": "4.2.4"
            },
            {
              "status": "affected",
              "version": "4.2.5"
            },
            {
              "status": "affected",
              "version": "4.2.6"
            },
            {
              "status": "affected",
              "version": "4.2.7"
            },
            {
              "status": "affected",
              "version": "4.2.8"
            },
            {
              "status": "affected",
              "version": "4.2.9"
            },
            {
              "status": "affected",
              "version": "4.2.10"
            },
            {
              "status": "affected",
              "version": "4.2.11"
            },
            {
              "status": "affected",
              "version": "4.2.12"
            },
            {
              "status": "affected",
              "version": "4.2.13"
            },
            {
              "status": "affected",
              "version": "4.2.14"
            },
            {
              "status": "affected",
              "version": "4.2.15"
            },
            {
              "status": "affected",
              "version": "4.2.16"
            },
            {
              "status": "affected",
              "version": "4.2.17"
            },
            {
              "status": "affected",
              "version": "4.2.18"
            },
            {
              "status": "affected",
              "version": "4.2.19"
            },
            {
              "status": "affected",
              "version": "4.2.20"
            },
            {
              "status": "affected",
              "version": "4.2.21"
            },
            {
              "status": "affected",
              "version": "4.2.22"
            },
            {
              "status": "affected",
              "version": "4.2.23"
            },
            {
              "status": "affected",
              "version": "4.2.24"
            },
            {
              "status": "affected",
              "version": "4.2.25"
            },
            {
              "status": "affected",
              "version": "4.3.0"
            },
            {
              "status": "affected",
              "version": "4.3.1"
            },
            {
              "status": "affected",
              "version": "4.3.2"
            },
            {
              "status": "affected",
              "version": "4.3.3"
            },
            {
              "status": "affected",
              "version": "4.3.4"
            },
            {
              "status": "unaffected",
              "version": "4.3.5"
            },
            {
              "status": "unaffected",
              "version": "4.4.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "chenhuanlin (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T04:30:10.101Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-410869 | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/410869"
        },
        {
          "name": "VDB-410869 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/410869/cti"
        },
        {
          "name": "CVE-2026-100909 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-100909"
        },
        {
          "name": "Submit #919993 | octobercms October CMS \u003c= 4.3.4  Path Traversal",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/919993"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://github.com/octobercms/october/security/advisories/GHSA-2xmm-m4wv-3fjh"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/0xGenesi/CVE/blob/main/October_CMS_Stream_Wrapper_Injection.md"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/octobercms/october/commit/0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/octobercms/october/releases/tag/v4.3.5"
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-27T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-27T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-27T12:24:21.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-100909",
    "datePublished": "2026-09-28T04:30:10.101Z",
    "dateReserved": "2026-09-27T10:19:16.000Z",
    "dateUpdated": "2026-09-28T12:48:33.093Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100901 (GCVE-0-2026-100901)

Vulnerability from cvelistv5 – Published: 2026-09-28 02:45 – Updated: 2026-09-28 12:46
VLAI
Title
athlon1600 youtube-downloader stream.php stream server-side request forgery
Summary
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 12:43 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
References
URL Tags
https://vuldb.com/vuln/410851 vdb-entrytechnical-description
https://vuldb.com/vuln/410851/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-100901 third-party-advisory
https://vuldb.com/submit/919147 third-party-advisory
https://gist.github.com/qianqiusujiu/87a7d7d8bd7f… exploit
Impacted products
Vendor Product Version
athlon1600 youtube-downloader Affected: 4.0.0
Affected: 4.0.1
    cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100901",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T12:43:15.422685Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T12:46:00.957Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:athlon1600:youtube-downloader:*:*:*:*:*:*:*:*"
          ],
          "product": "youtube-downloader",
          "vendor": "athlon1600",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0"
            },
            {
              "status": "affected",
              "version": "4.0.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "qianqiu (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 \u0027better security for public/stream.php\u0027 only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T02:45:10.743Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-410851 | athlon1600 youtube-downloader stream.php stream server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/410851"
        },
        {
          "name": "VDB-410851 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/410851/cti"
        },
        {
          "name": "CVE-2026-100901 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-100901"
        },
        {
          "name": "Submit #919147 | Athlon1600 youtube-downloader 6c117f09 (master, 2026-06-02) SSRF (Server-Side Request Forgery)",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/919147"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://gist.github.com/qianqiusujiu/87a7d7d8bd7fb53cf8529e0bafbeafba"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-27T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-27T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-27T10:54:58.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "athlon1600 youtube-downloader stream.php stream server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-100901",
    "datePublished": "2026-09-28T02:45:10.743Z",
    "dateReserved": "2026-09-27T08:49:53.864Z",
    "dateUpdated": "2026-09-28T12:46:00.957Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100900 (GCVE-0-2026-100900)

Vulnerability from cvelistv5 – Published: 2026-09-28 02:30 – Updated: 2026-10-01 14:00
VLAI
Title
DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery
Summary
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:59 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
References
URL Tags
https://vuldb.com/vuln/410850 vdb-entrytechnical-description
https://vuldb.com/vuln/410850/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-100900 third-party-advisory
https://vuldb.com/submit/919154 third-party-advisory
https://github.com/dddwmr/CVE/blob/main/Server-Si… exploit
Impacted products
Vendor Product Version
DevaslanPHP project-management Affected: 1.2.1
Affected: 1.2.2
Affected: 1.2.3
Affected: 1.2.4
Affected: v2.0.0-beta1
    cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100900",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T13:59:55.674392Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T14:00:55.894Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Jira Import"
          ],
          "product": "project-management",
          "vendor": "DevaslanPHP",
          "versions": [
            {
              "status": "affected",
              "version": "1.2.1"
            },
            {
              "status": "affected",
              "version": "1.2.2"
            },
            {
              "status": "affected",
              "version": "1.2.3"
            },
            {
              "status": "affected",
              "version": "1.2.4"
            },
            {
              "status": "affected",
              "version": "v2.0.0-beta1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "dwmm (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 6.5,
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T02:30:09.844Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-410850 | DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/410850"
        },
        {
          "name": "VDB-410850 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/410850/cti"
        },
        {
          "name": "CVE-2026-100900 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-100900"
        },
        {
          "name": "Submit #919154 | DevaslanPHP project-management \u22641.2.4/2.0.0-beta1 Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/919154"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/dddwmr/CVE/blob/main/Server-Side%20Request%20Forgery%20in%20Jira%20Import%20via%20Controllable%20Host%20and%20Missing%20canAccess%20.md"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-27T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-27T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-27T10:52:54.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-100900",
    "datePublished": "2026-09-28T02:30:09.844Z",
    "dateReserved": "2026-09-27T08:47:39.646Z",
    "dateUpdated": "2026-10-01T14:00:55.894Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100893 (GCVE-0-2026-100893)

Vulnerability from cvelistv5 – Published: 2026-09-28 00:45 – Updated: 2026-09-28 12:56
VLAI
Title
Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery
Summary
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 12:55 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
References
URL Tags
https://vuldb.com/vuln/410843 vdb-entrytechnical-description
https://vuldb.com/vuln/410843/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-100893 third-party-advisory
https://vuldb.com/submit/917632 third-party-advisory
https://is.yuum.me/posts/2026-08-06-ssrf-vulnerab… exploit
Impacted products
Vendor Product Version
Privoce VoceChat Server Affected: 0.5.0
Affected: 0.5.1
Affected: 0.5.2
Affected: 0.5.3
Affected: 0.5.4
Affected: 0.5.5
Affected: 0.5.6
Affected: 0.5.7
Affected: 0.5.8
Affected: 0.5.9
Affected: 0.5.10
Affected: 0.5.11
Affected: 0.5.12
Affected: 0.5.13
Affected: 0.5.14
Affected: 0.5.15
Affected: 0.5.16
Affected: 0.5.17
Affected: 0.5.18
Affected: 0.5.19
Affected: 0.5.20
Affected: 0.5.21
Affected: 0.5.22
Affected: 0.5.23
Affected: 0.5.24
Affected: 0.5.25
Affected: 0.5.26
Affected: 0.5.27
Affected: 0.5.28
Affected: 0.5.29
Affected: 0.5.30
Affected: 0.5.31
Affected: 0.5.32
Affected: 0.5.33
Affected: 0.5.34
Affected: 0.5.35
Affected: 0.5.36
    cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100893",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T12:55:57.650442Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T12:56:10.518Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "open_graphic_parse Endpoint"
          ],
          "product": "VoceChat Server",
          "vendor": "Privoce",
          "versions": [
            {
              "status": "affected",
              "version": "0.5.0"
            },
            {
              "status": "affected",
              "version": "0.5.1"
            },
            {
              "status": "affected",
              "version": "0.5.2"
            },
            {
              "status": "affected",
              "version": "0.5.3"
            },
            {
              "status": "affected",
              "version": "0.5.4"
            },
            {
              "status": "affected",
              "version": "0.5.5"
            },
            {
              "status": "affected",
              "version": "0.5.6"
            },
            {
              "status": "affected",
              "version": "0.5.7"
            },
            {
              "status": "affected",
              "version": "0.5.8"
            },
            {
              "status": "affected",
              "version": "0.5.9"
            },
            {
              "status": "affected",
              "version": "0.5.10"
            },
            {
              "status": "affected",
              "version": "0.5.11"
            },
            {
              "status": "affected",
              "version": "0.5.12"
            },
            {
              "status": "affected",
              "version": "0.5.13"
            },
            {
              "status": "affected",
              "version": "0.5.14"
            },
            {
              "status": "affected",
              "version": "0.5.15"
            },
            {
              "status": "affected",
              "version": "0.5.16"
            },
            {
              "status": "affected",
              "version": "0.5.17"
            },
            {
              "status": "affected",
              "version": "0.5.18"
            },
            {
              "status": "affected",
              "version": "0.5.19"
            },
            {
              "status": "affected",
              "version": "0.5.20"
            },
            {
              "status": "affected",
              "version": "0.5.21"
            },
            {
              "status": "affected",
              "version": "0.5.22"
            },
            {
              "status": "affected",
              "version": "0.5.23"
            },
            {
              "status": "affected",
              "version": "0.5.24"
            },
            {
              "status": "affected",
              "version": "0.5.25"
            },
            {
              "status": "affected",
              "version": "0.5.26"
            },
            {
              "status": "affected",
              "version": "0.5.27"
            },
            {
              "status": "affected",
              "version": "0.5.28"
            },
            {
              "status": "affected",
              "version": "0.5.29"
            },
            {
              "status": "affected",
              "version": "0.5.30"
            },
            {
              "status": "affected",
              "version": "0.5.31"
            },
            {
              "status": "affected",
              "version": "0.5.32"
            },
            {
              "status": "affected",
              "version": "0.5.33"
            },
            {
              "status": "affected",
              "version": "0.5.34"
            },
            {
              "status": "affected",
              "version": "0.5.35"
            },
            {
              "status": "affected",
              "version": "0.5.36"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "yumeu (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T00:45:15.919Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-410843 | Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/410843"
        },
        {
          "name": "VDB-410843 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/410843/cti"
        },
        {
          "name": "CVE-2026-100893 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-100893"
        },
        {
          "name": "Submit #917632 | Privoce, Inc VoceChat Server \u003c= 0.5.20 Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/917632"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://is.yuum.me/posts/2026-08-06-ssrf-vulnerability-in-vocechat-server-v0520/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-27T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-27T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-27T10:18:47.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-100893",
    "datePublished": "2026-09-28T00:45:15.919Z",
    "dateReserved": "2026-09-27T08:13:43.009Z",
    "dateUpdated": "2026-09-28T12:56:10.518Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100863 (GCVE-0-2026-100863)

Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:24
VLAI
Title
Heym before 0.0.91 SSRF via image fetching and IPv6 validation
Summary
Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client; because the workflow DSL supports "imageInput": "$userInput.body.imageUrl", a webhook or API caller can choose the fetch target when a workflow author uses that expression, allowing requests to loopback, RFC1918, and cloud metadata endpoints. Second, _is_public_address unwrapped only IPv4-mapped IPv6 addresses, so IPv6 transition forms — the NAT64 well-known prefix 64:ff9b::/96, deprecated IPv4-compatible ::x.x.x.x addresses, and 6to4 (2002::/16, classified as globally routable by Python 3.11.0 through 3.11.9) — could carry loopback, RFC1918, link-local, or cloud-metadata IPv4 destinations past both the initial URL validation and the dial-time IP pin. Version 0.0.91 routes the image loader through guard_http_url and the guarded client, evaluates NAT64 and IPv4-compatible addresses by their embedded IPv4 address, and refuses 64:ff9b:1::/48, 6to4, and Teredo (2001::/32) outright.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:23 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
heymrun heym Affected: 0 , < 0.0.91 (semver)
Unaffected: 0.0.91 (semver)
Create a notification for this product.
Date Public
2026-08-15 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100863",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T15:23:50.708780Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T15:24:03.334Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "heym",
          "vendor": "heymrun",
          "versions": [
            {
              "lessThan": "0.0.91",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0.0.91",
              "versionType": "semver"
            }
          ]
        }
      ],
      "datePublic": "2026-08-15T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme check and bypassing the egress-pinning HTTP client; because the workflow DSL supports \"imageInput\": \"$userInput.body.imageUrl\", a webhook or API caller can choose the fetch target when a workflow author uses that expression, allowing requests to loopback, RFC1918, and cloud metadata endpoints. Second, _is_public_address unwrapped only IPv4-mapped IPv6 addresses, so IPv6 transition forms \u2014 the NAT64 well-known prefix 64:ff9b::/96, deprecated IPv4-compatible ::x.x.x.x addresses, and 6to4 (2002::/16, classified as globally routable by Python 3.11.0 through 3.11.9) \u2014 could carry loopback, RFC1918, link-local, or cloud-metadata IPv4 destinations past both the initial URL validation and the dial-time IP pin. Version 0.0.91 routes the image loader through guard_http_url and the guarded client, evaluates NAT64 and IPv4-compatible addresses by their embedded IPv4 address, and refuses 64:ff9b:1::/48, 6to4, and Teredo (2001::/32) outright."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T01:28:52.561Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-6rph-qqcv-jqh4)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/heymrun/heym/security/advisories/GHSA-6rph-qqcv-jqh4"
        },
        {
          "name": "VulnCheck Advisory: Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/heym-before-0.0.91-ssrf-via-image-fetching-and-ipv6-validation"
        }
      ],
      "title": "Heym before 0.0.91 SSRF via image fetching and IPv6 validation",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100863",
    "datePublished": "2026-09-27T01:28:52.561Z",
    "dateReserved": "2026-09-27T00:20:54.407Z",
    "dateUpdated": "2026-09-30T15:24:03.334Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100861 (GCVE-0-2026-100861)

Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-28 13:38
VLAI
Title
heym before 0.0.105 SSRF via credential-controlled base URLs
Summary
heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 13:38 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
heymrun heym Affected: 0 , < 0.0.105 (semver)
Unaffected: 0.0.105 (semver)
Create a notification for this product.
Date Public
2026-09-03 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100861",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-28T13:38:17.642917Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-28T13:38:46.572Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "heym",
          "vendor": "heymrun",
          "versions": [
            {
              "lessThan": "0.0.105",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0.0.105",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "fatihkaratash"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "mbakgun"
        }
      ],
      "datePublic": "2026-09-03T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read internal service responses returned as workflow node output."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T01:28:51.256Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-xchj-mw74-2232)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/heymrun/heym/security/advisories/GHSA-xchj-mw74-2232"
        },
        {
          "name": "VulnCheck Advisory: heym before 0.0.105 SSRF via credential-controlled base URLs",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/heym-before-0.0.105-ssrf-via-credential-controlled-base-urls"
        }
      ],
      "title": "heym before 0.0.105 SSRF via credential-controlled base URLs",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100861",
    "datePublished": "2026-09-27T01:28:51.256Z",
    "dateReserved": "2026-09-27T00:20:03.854Z",
    "dateUpdated": "2026-09-28T13:38:46.572Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-100859 (GCVE-0-2026-100859)

Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 15:23
VLAI
Title
Heym before 0.0.106 Credential Exfiltration via URL Override
Summary
Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:22 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
heymrun heym Affected: 0 , < 0.0.106 (semver)
Unaffected: 0.0.106 (semver)
Create a notification for this product.
Date Public
2026-09-05 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-100859",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T15:22:55.534844Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T15:23:06.521Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "heym",
          "vendor": "heymrun",
          "versions": [
            {
              "lessThan": "0.0.106",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0.0.106",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "roonakyadav"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "mbakgun"
        }
      ],
      "datePublic": "2026-09-05T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner\u0027s secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T01:28:49.880Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-39qx-wp7x-69rq)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/heymrun/heym/security/advisories/GHSA-39qx-wp7x-69rq"
        },
        {
          "name": "VulnCheck Advisory: Heym before 0.0.106 Credential Exfiltration via URL Override",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/heym-before-0.0.106-credential-exfiltration-via-url-override"
        }
      ],
      "title": "Heym before 0.0.106 Credential Exfiltration via URL Override",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-100859",
    "datePublished": "2026-09-27T01:28:49.880Z",
    "dateReserved": "2026-09-27T00:20:03.854Z",
    "dateUpdated": "2026-09-30T15:23:06.521Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

No mitigation information available for this CWE.

CAPEC-664: Server Side Request Forgery

An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server’s internal network, or to external third parties. If successful, the adversary’s request will be made with the server’s privilege level, bypassing its authentication controls. This ultimately allows the adversary to access sensitive data, execute commands on the server’s network, and make external requests with the stolen identity of the server. Server Side Request Forgery attacks differ from Cross Site Request Forgery attacks in that they target the server itself, whereas CSRF attacks exploit an insecure user authentication mechanism to perform unauthorized actions on the user's behalf.