Tag
#SSRF
Critical Server-Side Request Forgery Vulnerability in Microsoft Purview Data Governance (CVE-2026-57106)
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-57106, with a CVSS score of 10, has been identified in Microsoft Purview Data Governance. This vulnerability allows an unauthorized attacker to elevate privileges over a network. Immediate action is required to mitigate this critical vulnerability.
Next.js Server-Side Request Forgery Vulnerability in Rewrites via Attacker-Controlled Destination Hostname
A critical vulnerability (CVE-2026-64645) has been discovered in Next.js, a popular React-based framework for building server-rendered, statically generated, and performance-optimized web applications. This vulnerability allows for Server-Side Request Forgery (SSRF) in rewrites via attacker-controlled destination hostnames, with a CVSS score of 8.3. The vulnerability affects Next.js versions >= 12.0.0 and < 15.5.21, as well as versions >= 16.0.0 and < 16.2.11. Immediate patching or workarounds are recommended to prevent potential SSRF attacks.
CVE-2026-16221: fast-uri Vulnerability Allows URL Parsing Discrepancies and Potential SSRF Attacks
A high-severity vulnerability (CVE-2026-16221, CVSS 7.5) exists in fast-uri versions 2.3.1 through 4.1.0, which can lead to URL parsing discrepancies when used with Node's native WHATWG URL parser. This discrepancy can be exploited to bypass host-based security policies, potentially allowing SSRF attacks or steering to unintended destinations, including cloud metadata endpoints or internal hosts. Affected applications should upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3 immediately.
Understanding and Defending Against Server-Side Request Forgery (SSRF) in PraisonAI
This educational analysis covers CVE-2026-61430, a server-side request forgery (SSRF) vulnerability in PraisonAI versions before 1.6.78. The vulnerability allows attackers to bypass SSRF protection using DNS rebinding and retrieve internal HTTP response bodies from private or loopback services. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection strategies, and defensive recommendations.
Critical Confused-Deputy Flaw in Grafana MCP Server Enables Token Exfiltration and SSRF
A high-severity vulnerability (CVE-2026-15583, CVSS 8.6) in Grafana MCP Server allows unauthenticated remote attackers to exfiltrate environment-configured Grafana service-account tokens and conduct SSRF attacks against internal services. The flaw has not been actively exploited but poses a significant risk due to its potential impact. Organizations using Grafana MCP Server version 0.17.1 or earlier are advised to upgrade immediately.
Understanding the oras-go Credential Forwarding Vulnerability via Unvalidated Location Header
The oras-go library is vulnerable to a credential forwarding issue due to an unvalidated Location header during the monolithic blob upload flow. This allows an attacker to leak credentials to an attacker-controlled endpoint and perform client-side SSRF. The vulnerability affects versions prior to 2.6.1 and is tracked under CVE-2026-50151.
Apify Model Context Protocol (MCP) Server: Actor MCP Path Authority Injection Leaks Apify Token
A vulnerability in `@apify/actors-mcp-server` version `0.10.7` allows an attacker to inject a malicious `webServerMcpPath` value, causing the MCP client to exfiltrate the victim's Apify API token to the attacker's server. This is a Server-Side Request Forgery (SSRF) / URL authority injection vulnerability with a CVSS Base Score of 8.1 (High).
CVE-2026-2053: WSO2 API Manager WS-Addressing Header Manipulation Vulnerability
A critical vulnerability (CVE-2026-2053) in WSO2 API Manager's message flow component allows unauthenticated attackers to manipulate WS-Addressing headers, potentially leading to unauthorized access to internal network resources. The vulnerability has a CVSS score of 8.3 and is considered high severity. Affected versions include WSO2 API Manager 3.1.0 to 4.2.0. Immediate patching is recommended.
Lokka Azure Resource Manager URL Path Validation Issue: Critical SSRF Vulnerability
A critical Server-Side Request Forgery (SSRF) vulnerability was discovered in Lokka versions prior to 2.1.2. The issue allows attackers to craft malicious URLs that can alter Azure Resource Manager bearer token transmission, potentially leading to unauthorized access. The vulnerability has a CVSS score of 8.7 and is categorized under CWE-918. Immediate patching to version 2.1.2 or later is strongly recommended.
Understanding and Mitigating Unsafe Remote Filename Resolution in Docling Core
A vulnerability in Docling Core, tracked as CVE-2026-44023, allows for unsafe remote filename resolution, potentially leading to SSRF attacks. This issue affects versions >= 1.5.0 and < 2.74.1 of docling-core. The vulnerability has been patched in version 2.74.1.