216.73.216.36

CVE-2026-5936

· Published 13/04/2026 07:16 · Modified 13/04/2026 15:01

Labels: CVE-2026-5936 14984358-7092-470d-8f34-ade47a7658a22026-04-13CVE-2026-5936CWE-918

Essential information

Published
13/04/2026 07:16
Modified
13/04/2026 15:01
Author
Creator
CVSS
8.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CVSS metrics

Description

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
14984358-7092-470d-8f34-ade47a7658a2
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / * cpe:2.3:*:*:*:*:*:*:*:*:*:*:*

References