Description
OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permission to configure notification channels can trigger requests to hosts reachable from the OpenCVE server, including internal network resources, localhost interfaces, link-local addresses, and cloud metadata services, and retrieve information from reachable HTTP services. This issue is fixed in version 3.0.0.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery enabling internal network data retrieval
Action: Apply Update
AI Analysis

Impact

OpenCVE allows a logged‑in user with permission to configure notification channels to supply arbitrary HTTP or HTTPS destinations for Webhook and Slack deliveries. The platform will then make outbound requests to those URLs, potentially accessing internal services, localhost interfaces, link‑local addresses, or cloud metadata endpoints, and the response can be read by the attacker. This creates a vulnerability that can lead to confidentiality loss of internal information and possible enumeration of hidden resources.

Affected Systems

All OpenCVE instances running a version earlier than 3.0.0 are vulnerable. The flaw exists in the notification testing component that processes user‑supplied webhook and Slack URLs.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity. The EPSS score is < 1%, and the flaw is not yet listed in the CISA KEV catalog. Exploitation requires an authenticated user with permission to modify notification channels; the attacker can craft malicious URLs to cause the server to perform requests against any host reachable from the OpenCVE server, including internal and cloud metadata services. The impact is limited to data disclosure through outbound HTTP traffic, but the ability to reach internal networks elevates risk for organizations with sensitive internal resources.

Generated by OpenCVE AI on September 19, 2026 at 18:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenCVE to version 3.0.0 or later, which removes the inadequate URL validation in notification configuration.
  • If an upgrade cannot be performed immediately, disable Webhook and Slack notification integrations until a patch is available or limit the set of allowed outbound URLs to a strict whitelist.
  • Revoke notification channel configuration rights from users who do not require them and enforce role‑based access control to prevent unauthorized URL submission.

Generated by OpenCVE AI on September 19, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ch3g-4xvr-674q OpenCVE: Server-Side Request Forgery (SSRF) in notifications
History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Opencve
Opencve opencve
Vendors & Products Opencve
Opencve opencve

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permission to configure notification channels can trigger requests to hosts reachable from the OpenCVE server, including internal network resources, localhost interfaces, link-local addresses, and cloud metadata services, and retrieve information from reachable HTTP services. This issue is fixed in version 3.0.0.
Title OpenCVE: Server-Side Request Forgery (SSRF) in notifications
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:27:47.474Z

Reserved: 2026-07-13T18:37:08.487Z

Link: CVE-2026-62282

cve-icon Vulnrichment

Updated: 2026-09-22T14:27:40.383Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:17:19.500

Modified: 2026-09-23T17:17:49.553

Link: CVE-2026-62282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:04:45Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)