Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhrh-vggg-q3rj

Опубликовано: 21 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 9.3

Описание

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network reconnaissance.

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network reconnaissance.

EPSS

Процентиль: 16%
0.00246
Низкий

9.2 Critical

CVSS4

9.3 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.3
nvd
18 дней назад

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network reconnaissance.

EPSS

Процентиль: 16%
0.00246
Низкий

9.2 Critical

CVSS4

9.3 Critical

CVSS3

Дефекты

CWE-918