Ssrf

8 posts tagged with “Ssrf”

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)
cvelibreofficelibreoffice-calc

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

How to fix CVE-2026-63277: upgrade LibreOffice to 26.2.5 or 26.8.0. A saved Calc external data link could load a remote Java driver on open; five sibling file-read, file-write and SSRF bugs are fixed in the same release.

Oct 5, 2026
Read
BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release
cvenextjsssrf

BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release

How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8

Sep 30, 2026
Read
BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster
cveopenshiftssrf

BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster

CVE-2026-75885 fixes are available for OpenShift 4.12, 4.17, 4.18, 4.19, 4.20, 4.21, and 4.22.

Sep 18, 2026
Read
BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF
cveopenmaicssrf

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF

How to fix CVE-2026-86259: upgrade OpenMAIC to 1.0.1

Sep 6, 2026
Read
BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts
cveollamassrf

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: upgrade Ollama to 0.34.2 or later

Sep 3, 2026
Read
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
cvechainlitmcp

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

Aug 25, 2026
Read
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
cveapache-hiveauthn

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

Aug 25, 2026
Read
CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding
cvefast-urissrf

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding

How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

Aug 24, 2026
Read