Impact
An unauthenticated server‑side request forgery flaw exists in the Dub metatags edge endpoint. The endpoint accepts a caller‑supplied URL and performs an HTTP request to that address without any denylist or authentication checks. Because the attacker can specify arbitrary URLs, the flaw can be used to probe internal network services or to exfiltrate sensitive information from cloud metadata endpoints. The weakness is a classic SRRF (CWE‑918) and therefore poses a significant risk to confidentiality and availability of internal resources when reachable files or services are targeted.
Affected Systems
The product affected is Dub: Dub from Dub. No affected‑version details are provided; it is understood that all releases up to at least 2026‑07‑10 are vulnerable. No vendor‑specific versioning or patch information is available in the supplied data.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity with the possibility of remote impact. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying no publicly known widespread exploitation at this time. Nonetheless, the lack of authentication and denial controls makes exploitation straightforward, typically by issuing an HTTP request to the vulnerable endpoint with a malicious URL parameter. Once executed, the server may contact any reachable host, revealing network topology or leaking confidential data, and could be leveraged for further attacks.
OpenCVE Enrichment