CVE-2026-22681
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access int
CVSS
8.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 21, 2026 · Last modified: Aug 21, 2026 · CWE-918
Not enough EPSS history yet.
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.
- github.comhttps://github.com/volcengine/OpenViking/commit/41e345896d247e43ab78bbcb38b4a5b1b38ef62c
- github.comhttps://github.com/volcengine/OpenViking/pull/1133
- github.comhttps://github.com/volcengine/OpenViking/releases/tag/v0.3.4
- www.vulncheck.comhttps://www.vulncheck.com/advisories/openviking-ssrf-via-api-v1-resources
- github.comhttps://github.com/volcengine/OpenViking/pull/1133https://github.com/volcengine/OpenViking/pull/1133