Description
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated server‑side request forgery flaw exists in the Dub metatags edge endpoint. The endpoint accepts a caller‑supplied URL and performs an HTTP request to that address without any denylist or authentication checks. Because the attacker can specify arbitrary URLs, the flaw can be used to probe internal network services or to exfiltrate sensitive information from cloud metadata endpoints. The weakness is a classic SRRF (CWE‑918) and therefore poses a significant risk to confidentiality and availability of internal resources when reachable files or services are targeted.

Affected Systems

The product affected is Dub: Dub from Dub. No affected‑version details are provided; it is understood that all releases up to at least 2026‑07‑10 are vulnerable. No vendor‑specific versioning or patch information is available in the supplied data.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity with the possibility of remote impact. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying no publicly known widespread exploitation at this time. Nonetheless, the lack of authentication and denial controls makes exploitation straightforward, typically by issuing an HTTP request to the vulnerable endpoint with a malicious URL parameter. Once executed, the server may contact any reachable host, revealing network topology or leaking confidential data, and could be leveraged for further attacks.

Generated by OpenCVE AI on August 11, 2026 at 17:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑provided patch or upgrade to the latest Dub release as soon as available
  • Prevent unauthenticated use of the metatags edge endpoint by enforcing authentication or IP‑based network rules
  • Restrict outbound traffic from the Dub server, especially to internal hosts and cloud metadata services, and monitor for anomalous requests

Generated by OpenCVE AI on August 11, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Dub
Dub dub
Vendors & Products Dub
Dub dub

Tue, 11 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints.
Title Dub Dub - Server-Side Request Forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-11T15:15:46.414Z

Reserved: 2026-08-10T10:32:49.081Z

Link: CVE-2026-72552

cve-icon Vulnrichment

Updated: 2026-08-11T15:15:39.246Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:40.860

Modified: 2026-08-11T16:17:35.570

Link: CVE-2026-72552

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T11:10:50Z

Links: CVE-2026-72552 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:42Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)