Description
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that enables a client‑side attacker to instruct the browser to send HTTP requests to arbitrary URLs. The vulnerability allows the browser to issue requests that appear to originate from the victim’s system, potentially giving the attacker the ability to probe internal resources or send data to external hosts. This is a typical instance of CWE‑918, where client‑initiated requests are redirected to unintended targets.

Affected Systems

All Microsoft Edge installations that use the Chromium engine are potentially affected, as the CNA vendor/product lists Microsoft Edge (Chromium‑based) without specifying particular builds or patch levels. Administrators should consider every current release of Edge as vulnerable until a patched version is applied.

Risk and Exploitability

The CVSS score of 7.4 classifies the flaw as high severity, while an EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at present. The vulnerability has not yet been listed in the CISA KEV catalog. Attackers would need to deliver malicious or specially crafted web content that causes Edge to perform an unintended request, which is typically achieved by convincing a user to visit a compromised site or by injecting user‑controlled data into a web page. Given the lack of publicly available exploits, the immediate risk remains moderate for environments that reject untrusted web content or tightly control browser usage.

Generated by OpenCVE AI on July 21, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that contains the SSRF fix.
  • Configure network perimeter defenses to block Edge from accessing internal or private IP ranges.
  • Enforce browser usage policies that restrict Edge from loading malicious or untrusted content, such as enabling Safe Browsing or restricting JavaScript execution in untrusted sites.

Generated by OpenCVE AI on July 21, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:33.763Z

Reserved: 2026-06-26T17:45:44.855Z

Link: CVE-2026-57993

cve-icon Vulnrichment

Updated: 2026-07-06T15:55:21.225Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)