Description
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that permits an unauthorized attacker to perform spoofing over a network, as stated in the advisory. This issue is identified as CWE‑918 and enables the attacker to craft requests that the browser will forward to arbitrary network addresses, thereby manipulating internal traffic for spoofing purposes.

Affected Systems

The vulnerability affects Microsoft Edge (Chromium‑based). No specific version information is supplied, so all current and legacy builds may be impacted until a patch is applied.

Risk and Exploitability

The CVSS base score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The advisory does not explicitly state the attack vector, so the only confirmed detail is the existence of SSRF that permits network spoofing.

Generated by OpenCVE AI on July 23, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update through Windows Update or the Microsoft Update Catalog.
  • If an update is not yet available, download and install the security update package for CVE-2026-58278 from Microsoft.
  • As a temporary defense, block outbound requests to internal or untrusted hosts in your network firewall or configure Edge to restrict such traffic, and monitor outbound traffic for anomalies.

Generated by OpenCVE AI on July 23, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:30:07.670Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58278

cve-icon Vulnrichment

Updated: 2026-07-06T16:38:10.585Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T16:15:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)