CVE-2026-2377
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated
CVSS
6.5
Medium
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Apr 8, 2026 · Last modified: Sep 10, 2026 · CWE-918
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19375
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21017
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22629
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22840
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23361
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24853
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-2377
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2439201
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19375
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21017
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22629
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22840
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23361
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24853
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-2377
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2439201
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2377.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-760868.5 HIG—
——0Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while the server uses stored API keys or OAuth tokens, causing non-blind server-side requests to an attacker-controlled or internal host and returning the remote response. This residual flaw remained because the permission gate added in version 3.1.28 excluded the form-settings action. Sites that permit low-privileged or front-end user authentication can therefore expose integration credentials and internal network responses. This issue is fixed in versions 2.2.23 and 3.1.31.4hCVE-2026-966554.3 MED—
——0Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.6hCVE-2026-966524.3 MED—
——0Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.6hCVE-2026-771126.5 MED—
——0Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery.
This issue affects Weoll: before 3.2.45.44.6hCVE-2026-840465.0 MED7.9%
——2The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.5hCVE-2026-959306.3 MED36.6%
——11A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded.8h