Description
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that enables a client‑side attacker to instruct the browser to send HTTP requests to arbitrary URLs. The vulnerability allows the browser to issue requests that appear to originate from the victim’s system, potentially giving the attacker the ability to probe internal resources or send data to external hosts. This is a typical instance of CWE‑918, where client‑initiated requests are redirected to unintended targets.

Affected Systems

All Microsoft Edge installations that use the Chromium engine are potentially affected, as the CNA vendor/product lists Microsoft Edge (Chromium‑based) without specifying particular builds or patch levels. Administrators should consider every current release of Edge as vulnerable until a patched version is applied.

Risk and Exploitability

Based on the description, the likely attack vector is the delivery of malicious or specially crafted web content that causes Edge to perform an unintended request. The attacker can lure a user to visit a compromised site or inject user‑controlled data into a page. The CVSS score of 7.4 indicates high severity, but the EPSS score of less than 1 % suggests a low chance of widespread exploitation at present, and the vulnerability is not yet listed in CISA KEV. If exploited, the attacker can pose as the victim’s system to query internal resources or send data to external hosts, enabling internal reconnaissance or data exfiltration.

Generated by OpenCVE AI on August 1, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that contains the SSRF fix.
  • Configure network perimeter defenses to block Edge from accessing internal or private IP ranges.
  • Enforce browser usage policies that restrict Edge from loading malicious or untrusted content, such as enabling Safe Browsing or restricting JavaScript execution in untrusted sites.

Generated by OpenCVE AI on August 1, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:45.164Z

Reserved: 2026-06-26T17:45:44.855Z

Link: CVE-2026-57993

cve-icon Vulnrichment

Updated: 2026-07-06T15:55:21.225Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:02.443

Modified: 2026-07-06T19:23:34.363

Link: CVE-2026-57993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)