Description
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery
Action: Assess Impact
AI Analysis

Impact

A flaw in the open_graphic_parse endpoint of Privoce VoceChat Server allows an attacker to manipulate the URL parameter, causing the server to send HTTP requests to arbitrary destinations. This results in a server‑side request forgery vulnerability that can lead to disclosure of internal resources, internal network scanning, or the use of the server as a proxy to attack other services.

Affected Systems

Privoce VoceChat Server, versions up to and including 0.5.36 are affected.

Risk and Exploitability

The CVSS score of 6.9 signifies a moderate risk, and the vulnerability has already been publicly disclosed, enabling remote exploitation. EPSS data are unavailable and the flaw is not listed in CISA's KEV catalog. Because the vendor has not issued a patch, the risk remains until remediation steps are taken.

Generated by OpenCVE AI on September 28, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Privoce VoceChat Server to a version that contains the fix for the open_graphic_parse SSRF flaw.
  • Implement strict input validation on the URL parameter, allowing only trusted schemes and domains or rejecting all external URLs.
  • Configure network segmentation or firewall rules to block outbound connections from the VoceChat Server to internal IP ranges and sensitive services.
  • Monitor outbound traffic from the VoceChat Server for anomalous HTTP requests to detect and alert on potential SSRF attempts.

Generated by OpenCVE AI on September 28, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery
First Time appeared Privoce
Privoce vocechat Server
Weaknesses CWE-918
CPEs cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*
Vendors & Products Privoce
Privoce vocechat Server
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Privoce Vocechat Server
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T00:45:15.919Z

Reserved: 2026-09-27T08:13:43.009Z

Link: CVE-2026-100893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.020

Modified: 2026-09-28T02:17:19.020

Link: CVE-2026-100893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T02:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)