Impact
HyperDX before 2.31.0 contains a server‑side request forgery flaw that allows any authenticated team member to supply a host parameter to the ClickHouse proxy test endpoint. Because the application sanitises input only loosely, the server will forward the request to whatever internal address the attacker chooses. The endpoint then returns the raw response from the target, so an attacker can read the contents of internal APIs, container‑host interfaces and cloud‑provider metadata services, thereby leaking sensitive configuration and authentication data and potentially enabling lateral movement.
Affected Systems
The flaw affects all installations of HyperDX that use a version earlier than 2.31.0. No public CPEs are listed, but the product is identified as HyperDX by the CNA vendor hyperdxio. The security advisory recommends upgrading to release 2.31.0 or later. Varying internal deployments may expose different internal services to the SSRF attack depending on how the ClickHouse proxy is configured.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity vulnerability. The EPSS score of 0.00238 (< 1%) indicates a very low, but non‑zero, probability of exploitation, but the flaw is not listed in CISA's KEV catalog. Attackers would need authenticated access to the HyperDX environment to use the endpoint, so the threat is limited to compromised or insider users with team membership. Nevertheless, because the victim can read arbitrary internal service responses, the attack can facilitate discovery of secrets, credential endpoints, or other exploitable misconfigurations.
OpenCVE Enrichment