Threat Advisory

OpenCVE SSRF Vulnerability Allows Internal Service Interaction

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Server-Side Request Forgery (SSRF) vulnerability affecting opencve versions <= 1.5.0, identified as CVE-2026-62282 with a CVSS score of 6.5, exists in the notification testing functionality for both Webhook and Slack integrations within OpenCVE. An authenticated user can trigger test requests to arbitrary HTTP(S) endpoints, potentially interacting with internal services not accessible from the Internet and retrieving information from HTTP-based services reachable by the OpenCVE instance. This flaw type is categorized as CWE-918 and has a medium severity rating. The attack vector is network-based (AV:N), requiring low privileges (PR:L) and no user interaction (UI:N). Successful exploitation could have a high impact on confidentiality, allowing an attacker to access sensitive information. Affected versions of OpenCVE are not explicitly stated in the article; however, users should be aware that this vulnerability has been addressed in version 3.0.0 or later.

RECOMMENDATION:

We recommend you to update OpenCVE to version 3.0.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Server-Side Request Forgery (SSRF) vulnerability affecting opencve versions <= 1.5.0, identified as CVE-2026-62282 with a CVSS score of 6.5, exists in the notification testing functionality for both Webhook and Slack integrations within OpenCVE. An authenticated user can trigger test requests to arbitrary HTTP(S) endpoints, potentially interacting with internal services not accessible from the Internet and retrieving information from HTTP-based services reachable by the OpenCVE instance. This flaw type is categorized as CWE-918 and has a medium severity rating. The attack vector is network-based (AV:N), requiring low privileges (PR:L) and no user interaction (UI:N). Successful exploitation could have a high impact on confidentiality, allowing an attacker to access sensitive information. Affected versions of OpenCVE are not explicitly stated in the article; however, users should be aware that this vulnerability has been addressed in version 3.0.0 or later.

RECOMMENDATION:

We recommend you to update OpenCVE to version 3.0.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu