CVE-2026-32553
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVSS
7.2
Alto
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 18 ago 2026 · Última mod.: 20 ago 2026 · CWE-918
0.2%EPSS · 30 días0.3%
2026-08-192026-08-28
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-185454.3 MED—
——0IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.15hCVE-2026-822897.4 ALT—
——0Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled hostnames to trigger outbound connections to arbitrary hosts and disclose GitHub personal access tokens via HTTP basic credentials.15hCVE-2026-822858.2 ALT—
——0bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using caller-supplied object names.17hCVE-2026-822707.5 ALT—
——0Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.17hCVE-2026-822687.5 ALT—
——0Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.15hCVE-2026-822636.8 MED—
——0Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.15h