Skip to content
COOEY

EXPOSURES › CVE-2026-5936

CVE-2026-5936

HIGH
DETAIL
SourceNVD · cve Published2026-04-13 CVSS8.5 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-5936 ↗
SHAME 25/100

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata servic

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.