<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Server-Side Request Forgery (SSRF)</title>
  <link>https://cvedaily.com/pages/tags/ssrf.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ssrf.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Server-Side Request Forgery (SSRF)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20230 – A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20230</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20230</strong></p>
  <p>A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit thi…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10690 – A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10690</guid>
    <pubDate>Wed, 03 Jun 2026 00:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10690</strong></p>
  <p>A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16a…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49120 – Medplum before 5.1.14 contains a server-side request forgery vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49120</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49120</strong></p>
  <p>Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating FHIR Subscription resources with arbitrary endpoint URLs. Attackers can point subscription endpoints at internal addresses such as cloud instance metadata services, internal databases, or container orche…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8993 – D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Hand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8993</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8993</strong></p>
  <p>D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10583 – A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10583</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10583</strong></p>
  <p>A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project tagged the r…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10581 – A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10581</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10581</strong></p>
  <p>A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49139 – Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49139</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49139</strong></p>
  <p>Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subse…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49138 – Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49138</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49138</strong></p>
  <p>Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10287 – A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10287</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10287</strong></p>
  <p>A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10280 – A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10280</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10280</strong></p>
  <p>A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP API Call Endpoint. The manipulation of the argument serverBaseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10276 – A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10276</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10276</strong></p>
  <p>A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the prob…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10274 – A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10274</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10274</strong></p>
  <p>A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and m…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49328 – Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49328</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49328</strong></p>
  <p>Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10517 – A flaw was found in Clair. The fetcher component makes outbound HTTP requests to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10517</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10517</strong></p>
  <p>A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-in, not enforced by default), an unauthenticated attacker can submit a manifest with a URI pointing to internal services or cloud metadata endpoints. The SSRF is reflective for non-200…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10241 – A security flaw has been discovered in jeecgboot The server processes these URLs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10241</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10241</strong></p>
  <p>A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used fo…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10240 – A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10240</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10240</strong></p>
  <p>A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10239 – A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10239</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10239</strong></p>
  <p>A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. A fix is planned for the upcoming release.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10177 – A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10177</guid>
    <pubDate>Sun, 31 May 2026 11:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10177</strong></p>
  <p>A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. Th…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48555 – Spatie Laravel Media Library before version 11.23.0 contains a server-side reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48555</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48555</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44285 – FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44285</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44285</strong></p>
  <p>FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploiting an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49372 – In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49372</guid>
    <pubDate>Fri, 29 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49372</strong></p>
  <p>In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44652 – SillyTavern is a locally installed user interface that allows users to interact ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44652</guid>
    <pubDate>Fri, 29 May 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44652</strong></p>
  <p>SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, corsProxyMiddleware forwards req.params.url directly into fetch(url, ...). It only blocks circular requests to its own host and does not enforce destination allowlist or private/loopback restrictions…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10107 – MoviePilot v2 contains a server-side request forgery vulnerability in the image ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10107</guid>
    <pubDate>Fri, 29 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10107</strong></p>
  <p>MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a URL whose domain matches the assembled allowlist. Attackers can bypass internal network protections because the SecurityUtils.is_safe_url function performs only domain-membership checking without blo…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35673 – OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35673</guid>
    <pubDate>Fri, 29 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35673</strong></p>
  <p>OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocked tabs to export or inspect content that should remain protected.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10068 – A flaw has been found in Shibby Tomato 1.28. The affected element is the functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10068</guid>
    <pubDate>Fri, 29 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10068</strong></p>
  <p>A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45609 – mcp-security provides Security and Authorization support for Model Context Proto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45609</guid>
    <pubDate>Fri, 29 May 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45609</strong></p>
  <p>mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for OAuth-related discovery and metadata without verifying if the targets are malicious or inter…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9557 – A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9557</guid>
    <pubDate>Fri, 29 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9557</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45366 – typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45366</guid>
    <pubDate>Thu, 28 May 2026 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45366</strong></p>
  <p>typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HTTPS / loopback allowlist, but callTool() reuses the resolved toolCallTemplate.url directly without…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49093 – Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49093</guid>
    <pubDate>Thu, 28 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49093</strong></p>
  <p>Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42398 – Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42398</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42398</strong></p>
  <p>Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49129 – Music Player Daemon (MPD) before version 0.24.11 contains a server-side request ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49129</guid>
    <pubDate>Thu, 28 May 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49129</strong></p>
  <p>Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect to non-HTTP protocols such as gopher, ftp, sftp, ldap, dict, rtmp, or rtsp. Att…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46526 – Local Deep Research is an AI-powered research assistant for deep, iterative rese...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46526</guid>
    <pubDate>Thu, 28 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46526</strong></p>
  <p>Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The main logic is to perform security checks on the host portion of the URL extracted by urlparse to pre…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43979 – Local Deep Research is an AI-powered research assistant for deep, iterative rese...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43979</guid>
    <pubDate>Thu, 28 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43979</strong></p>
  <p>Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an f-string without any HTML escaping. An authenticated attacker can craft a researc…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45373 – CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, althou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45373</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45373</strong></p>
  <p>CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as http://[::1], the SSRF defenses do not work. This vulnerability is fixed in 0.8.26.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45310 – CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45310</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45310</strong></p>
  <p>CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the HTTP client (reqwest) is configured to automatically follow up to 5 redirects (reqw…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44797 – Nautobot is a Network Source of Truth and Network Automation Platform. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44797</guid>
    <pubDate>Thu, 28 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44797</strong></p>
  <p>Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48522 – PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48522</guid>
    <pubDate>Thu, 28 May 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48522</strong></p>
  <p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestio…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9813 – FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9813</guid>
    <pubDate>Thu, 28 May 2026 10:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9813</strong></p>
  <p>FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, a…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5737 – The Independent Analytics plugin for WordPress is vulnerable to Server-Side Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5737</guid>
    <pubDate>Thu, 28 May 2026 05:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5737</strong></p>
  <p>The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon fetcher that performs unrestricted cURL requests to stored domains. The signature v…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48146 – Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48146</guid>
    <pubDate>Wed, 27 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48146</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 t…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48128 – Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48128</guid>
    <pubDate>Wed, 27 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48128</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target internal infrastructure, this creates a server-side request forgery path where automation execution…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45717 – Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45717</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45717</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /api/datasources/:datasourceId). Every authenticated Budibase app user with the BASIC built-in role o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45061 – Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45061</guid>
    <pubDate>Wed, 27 May 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45061</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: url.includes(".tar.gz"). Any URL containing .tar.gz anywhere in the string — in the path, query string, or fragment — passes this check. The URL then proceeds directly to fetchWithBlacklist() with no further validation of host…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44353 – Streamlink is a CLI utility which pipes video streams from various services into...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44353</guid>
    <pubDate>Wed, 27 May 2026 17:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44353</strong></p>
  <p>Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. T…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44971 – GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44971</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44971</strong></p>
  <p>GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by G…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9312 – A server-side request forgery (SSRF) vulnerability was identified in GitHub Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9312</guid>
    <pubDate>Wed, 27 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9312</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potent…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8606 – A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8606</guid>
    <pubDate>Wed, 27 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8606</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, includ…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45412 – MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45412</guid>
    <pubDate>Tue, 26 May 2026 21:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45412</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2.9.1.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42336 – MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42336</guid>
    <pubDate>Tue, 26 May 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42336</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42335 – MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42335</guid>
    <pubDate>Tue, 26 May 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42335</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/oss/get_url) endpoint. The vulnerability exists due to inconsistent URL parsing between the urlparse validation function and the requests HTTP client, allowing attackers to access internal network serv…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2264 – A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2264</guid>
    <pubDate>Tue, 26 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2264</strong></p>
  <p>A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.  For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14290 – IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14290</guid>
    <pubDate>Tue, 26 May 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14290</strong></p>
  <p>IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40564 – Files or Directories Accessible to External Parties, Server-Side Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40564</guid>
    <pubDate>Tue, 26 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40564</strong></p>
  <p>Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.  The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR create permissions read files from the operator pod's filesystem and pull content from any backing store reachable through Flin…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45082 – Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45082</guid>
    <pubDate>Tue, 26 May 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45082</strong></p>
  <p>Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private network destinations, these protections could be bypassed through crafted HTTP red…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44598 – With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44598</guid>
    <pubDate>Mon, 25 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44598</strong></p>
  <p>With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.     This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.  Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue by encrypting th…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48843 – Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48843</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48843</strong></p>
  <p>Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9464 – A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9464</guid>
    <pubDate>Mon, 25 May 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9464</strong></p>
  <p>A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47076 – Interpretation Conflict vulnerability in benoitc hackney allows Server Side Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47076</guid>
    <pubDate>Mon, 25 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47076</strong></p>
  <p>Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{} record. OTP's uri_string:parse/1 and inet:parse_address/1 do not decode percent-escapes in the host, so a URL such as http://%31%32%37%2E%30%2E%30%2E%31/ is seen by a caller's allowlist validator wit…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9372 – A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9372</guid>
    <pubDate>Sun, 24 May 2026 11:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9372</strong></p>
  <p>A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early thro…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3515 – A vulnerability in the `GitHubRepository` block of the `prefect-github` integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3515</guid>
    <pubDate>Sun, 24 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3515</strong></p>
  <p>A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, lead…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9304 – A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9304</guid>
    <pubDate>Sat, 23 May 2026 14:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9304</strong></p>
  <p>A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit ha…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39965 – TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39965</guid>
    <pubDate>Fri, 22 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39965</strong></p>
  <p>TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow 302 redirects without re-validating the redirect destination. An authenticated user can point a bot…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34207 – TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34207</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34207</strong></p>
  <p>TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example that resolves to 127.0.0.1, 169.254.169.254, or RFC1918/private space passes validation and is late…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33712 – Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33712</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33712</strong></p>
  <p>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF valida…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7798 – The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7798</guid>
    <pubDate>Fri, 22 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7798</strong></p>
  <p>The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application an…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6394 – The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor &amp; FSE plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6394</guid>
    <pubDate>Wed, 20 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6394</strong></p>
  <p>The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it directly to wp_remote_get() without any URL validation or restriction against internal…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47358 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47358</guid>
    <pubDate>Tue, 19 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47358</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47357 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47357</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47357</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-g…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47356 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47356</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47356</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30118 – scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30118</guid>
    <pubDate>Tue, 19 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30118</strong></p>
  <p>scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and headers exposure and possible privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31910 – Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.

This issue af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31910</guid>
    <pubDate>Tue, 19 May 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31910</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29226 – Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29226</guid>
    <pubDate>Tue, 19 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29226</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33234 – AutoGPT is a workflow automation platform for creating, deploying, and managing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33234</guid>
    <pubDate>Tue, 19 May 2026 02:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33234</strong></p>
  <p>AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51,  SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution block inputs, then passes them directly to Python's smtplib.SMTP() to open a raw T…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8768 – A vulnerability was found in vercel ai up to 3.0.97. The affected element is the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8768</guid>
    <pubDate>Sun, 17 May 2026 23:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8768</strong></p>
  <p>A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8725 – A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8725</guid>
    <pubDate>Sun, 17 May 2026 02:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8725</strong></p>
  <p>A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about th…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45347 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45347</guid>
    <pubDate>Fri, 15 May 2026 22:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45347</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF) via the PDF generate function. In the PDF export, user inputs are interpreted as HTML and embedded into the PDF. According to tests, scripts and some potentially dangerous tags (iFrame, Object, etc.) are blocked, preventing server-…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45338 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45338</guid>
    <pubDate>Fri, 15 May 2026 22:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45338</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). The function fetches arbitrary URLs from OAuth picture claims without applying validate_url(), allowing an attacker to force the server to make HTTP…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45400 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45400</guid>
    <pubDate>Fri, 15 May 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45400</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability. This vulnerability is fixed in 0.9.5.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-47958 – CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47958</guid>
    <pubDate>Fri, 15 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-47958</strong></p>
  <p>CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39053 – Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39053</guid>
    <pubDate>Fri, 15 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39053</strong></p>
  <p>Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44661 – python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44661</guid>
    <pubDate>Thu, 14 May 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44661</strong></p>
  <p>python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / loopback allowlist, but call_tool() and call_tool_streaming() reuse the resolved tool_call_template.…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44520 – Docling-Graph turns documents into validated Pydantic objects, then builds a dir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44520</guid>
    <pubDate>Thu, 14 May 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44520</strong></p>
  <p>Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/core/input/handlers.py makes HTTP requests to user-supplied URLs without validating whether the target resolves to a private, loopback, or link-local IP address. The URLValidator only checks for a val…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44515 – Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud New...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44515</guid>
    <pubDate>Thu, 14 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44515</strong></p>
  <p>Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versions, an authenticated attacker could provide a URL pointing to internal/private IP ranges or localhost, causing the Nextcloud server to perform server-side HTTP requests to attacker-controlled destina…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42597 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42597</guid>
    <pubDate>Thu, 14 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42597</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request AllowedFilePrefixes guard to s…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42595 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42595</guid>
    <pubDate>Thu, 14 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42595</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chromium at any internal IP — including loopback, RFC 1918 ranges, and cloud metadata endpoints — and r…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42591 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42591</guid>
    <pubDate>Thu, 14 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42591</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42281 – MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42281</guid>
    <pubDate>Thu, 14 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42281</strong></p>
  <p>MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (**V…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44919 – In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44919</guid>
    <pubDate>Thu, 14 May 2026 02:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44919</strong></p>
  <p>In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-696</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44439 – PlaywrightCapture is a simple replacement for splash using playwright. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44439</guid>
    <pubDate>Wed, 13 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44439</strong></p>
  <p>PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the capture process open file:// URLs or request resources hosted on private, loopbac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44363 – MISP modules are autonomous modules that can be used to extend MISP for new serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44363</guid>
    <pubDate>Wed, 13 May 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44363</strong></p>
  <p>MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Addition…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0258 – A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0258</guid>
    <pubDate>Wed, 13 May 2026 19:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0258</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.    Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44578 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44578</guid>
    <pubDate>Wed, 13 May 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44578</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44015 – Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44015</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44015</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and ena…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41195 – mosparo is the modern solution to protect your online forms from spam. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41195</guid>
    <pubDate>Tue, 12 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41195</strong></p>
  <p>mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker-controlled URL that the server later fetches. Because the server follows http/https redirects and does not restrict private or loopback destinations, this becomes a stored SSRF primitive that can be…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44232 – DSSRF is a Node.js library that provides a wide range of utilities and advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44232</guid>
    <pubDate>Tue, 12 May 2026 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44232</strong></p>
  <p>DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.3.0, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.3.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-791</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34647 – Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34647</guid>
    <pubDate>Tue, 12 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34647</strong></p>
  <p>Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue requires user interaction in that a victim must…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43929 – ssrfcheck is a library that checks if a string contains a potential SSRF attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43929</guid>
    <pubDate>Tue, 12 May 2026 18:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43929</strong></p>
  <p>ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brackets to compressed hex form (…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42175 – requests-hardened is a library that overrides the default behaviors of the reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42175</guid>
    <pubDate>Tue, 12 May 2026 18:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42175</strong></p>
  <p>requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addresses within the RFC 6598 Shared Address Space (100.64.0.0/10). An attacker who can supply arbitrary URLs to requests-hardened could exploit this gap to access internal services hosted within 100.64.0…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42141 – Xibo is an open source digital signage platform with a web content management sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42141</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42141</strong></p>
  <p>Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43993 – JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-securit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43993</guid>
    <pubDate>Tue, 12 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43993</strong></p>
  <p>JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43993">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
