CVE-2026-65442
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVSS
7.2
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 27, 2026 · Last modified: Jul 27, 2026 · CWE-918
Not enough EPSS history yet.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-619537.2 HIG—
———Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.6hCVE-2026-659256.5 MED—
———A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.8hCVE-2026-659246.5 MED—
———JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.8hCVE-2026-659236.8 MED—
———A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.8hCVE-2026-656186.5 MED—
———Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.8hCVE-2026-64649——
———Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; next start and standalone output do the same from version 14.2 onward. This issue has been fixed in versions 15.5.21 and 16.2.11.9h