PULSE
LIVE32signals / 24h
FEED
ransomtermite reclama a Affinia Healthcare · US · Healthcareransomincransom reclama a minigrip.com.mx · MX · Manufacturingransomincransom reclama a DUCON · CO · Manufacturingransomincransom reclama a foundationstofreedom.org · US · Otherransomanubis reclama a Prelys Courtage · FR · Financial Servicesransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Educationransomtermite reclama a Affinia Healthcare · US · Healthcareransomincransom reclama a minigrip.com.mx · MX · Manufacturingransomincransom reclama a DUCON · CO · Manufacturingransomincransom reclama a foundationstofreedom.org · US · Otherransomanubis reclama a Prelys Courtage · FR · Financial Servicesransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Education
← All CVEs
CVE WatchJul 27, 2026

CVE-2026-65923

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions,

CVSS

6.8

Medium

EPSS

KEV

Exploit Today

0-100

Published: Jul 27, 2026 · Last modified: Jul 27, 2026 · CWE-918

EPSS · 30d

Not enough EPSS history yet.

Technical description

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654427.2 HIG
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.6h
CVE-2026-619537.2 HIG
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.6h
CVE-2026-659256.5 MED
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.8h
CVE-2026-659246.5 MED
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.8h
CVE-2026-656186.5 MED
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.8h
CVE-2026-64649
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; next start and standalone output do the same from version 14.2 onward. This issue has been fixed in versions 15.5.21 and 16.2.11.9h