Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53qf-qv6v-5586

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.

EPSS

Процентиль: 17%
0.00248
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.8
nvd
5 дней назад

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.

EPSS

Процентиль: 17%
0.00248
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-918