Description
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery.

This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.
Published: 2026-08-07
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (SSRF) that allows an attacker to send arbitrary HTTP requests from the Revenue Administration Türkiye's E‑Signature web application to internal destinations. This flaw can expose internal services, leak sensitive data, or facilitate further attacks such as network reconnaissance, but it does not grant code execution or clear‑text access on the host. The vulnerability is listed as CWE‑918, indicating insufficient input validation of URLs and host data.

Affected Systems

The issue affects the Revenue Administration Türkiye's E‑Signature application. All versions from 2.4.4.0 up to, but not including, 2.5.1.0 are vulnerable. Any deployment of these versions should be considered at risk until remedied.

Risk and Exploitability

The CVSS score of 5.4 classifies the weakness as medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower current exploitation pressure. However, the attack vector is likely an unauthenticated WebSocket API, inferred from the title, meaning that a remote attacker could trigger the SSRF without credentials. The risk to confidentiality and integrity of internal resources is moderate, especially if sensitive services are reachable from the application server. Due to the lack of available EPSS data, the exact likelihood of exploitation cannot be quantified, but the medium CVSS indicates that it should be addressed promptly.

Generated by OpenCVE AI on August 7, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the application to version 2.5.1.0 or later, which eliminates the SSRF flaw.
  • Restrict access to the WebSocket endpoint by requiring authentication or limiting traffic to trusted IP ranges, preventing unauthenticated exploitation.
  • Configure defensive network controls (firewalls or segmentation) so that the application server cannot reach internal services via local or private addresses, reducing the impact of any remaining SSRF risk.

Generated by OpenCVE AI on August 7, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.
Title Unauthenticated WebSocket-to-XAdES SSRF in Revenue Administration of Türkiye's E-Signature
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-07T08:49:59.862Z

Reserved: 2026-07-17T08:21:50.945Z

Link: CVE-2026-16027

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T08:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)