Description
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
Published: 2026-08-25
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a low-level user to instruct Artifactory to fetch resources from arbitrary remote CocoaPods repositories. This constitutes a server‑side request forgery, enabling an attacker to make outbound HTTP requests from the Artifactory host. While the CVSS score of 3.5 indicates a low severity, the ability to reach external systems could expose sensitive data or facilitate additional attacks if the fetched content is processed by other components.

Affected Systems

The affected product is JFrog Artifactory. No specific versions are listed in the data, so all deployed installations of Artifactory could be susceptible until a vendor‑supplied fix is applied.

Risk and Exploitability

The CVSS score of 3.5 reflects limited impact and low privilege escalation. EPSS data is unavailable, and the vulnerability is not in the CISA KEV catalog, meaning it is not currently known to be widely exploited. The likely attack vector is a local low-level user or compromised account that can invoke Artifactory’s external dependency resolution. Given the constraints, the risk is moderate for environments where Artifactory has unrestricted outbound network access, and priority should be placed on monitoring outbound traffic rather than immediate patching if no fix is available.

Generated by OpenCVE AI on August 25, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the JFrog Artifactory release notes and patch for a fix addressing this SSRF issue and apply it as soon as possible.
  • If no patch is available, disable or restrict the use of external dependencies in Artifactory’s configuration, or implement a whitelist that limits URLs to approved domains.
  • Configure firewall or network segmentation rules to block or monitor outbound connections from the Artifactory host, ensuring that only legitimate repository traffic is allowed.
  • Log and audit all outbound HTTP requests initiated by Artifactory to detect potential misuse of the SSRF mechanism.

Generated by OpenCVE AI on August 25, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
Title SSRF In CocoaPods Via JFrog Artifactory External Dependency
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-25T15:17:16.973Z

Reserved: 2026-08-04T18:29:25.512Z

Link: CVE-2026-70548

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T16:17:08.010

Modified: 2026-08-25T16:17:08.010

Link: CVE-2026-70548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T17:00:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)