Description
A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side Request Forgery (SSRF)
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the resolve-custom-domain-rewrite.ts file of the OpenstatusHQ Openstatus platform. By manipulating the custom domain rewrite logic, an attacker can cause the server to send outbound HTTP requests to arbitrary URLs. The attack may be initiated remotely, as the description indicates that a crafted remote request can trigger the flaw. The result is that the application performs server‑side request forgery, potentially giving an attacker the ability to reach internal or external resources and exfiltrate data or pivot further into the environment. This issue is categorized as CWE‑918.

Affected Systems

OpenstatusHQ’s Openstatus platform is vulnerable in all releases up to commit f04c827112f30a11d571ebdad3892826034d6265. Because the product follows a rolling release model, discrete version numbers are not available; the fix is identified by commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. Any deployment that has not yet incorporated that commit remains susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity rating. The EPSS score is reported as less than 1%, which suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw can be triggered remotely and allows the server to resolve arbitrary URLs, creating an opportunity for further attacks. Exploitation would involve sending a crafted request to the exposed endpoint, causing the server to contact a specified target and potentially exposing internal or public networks to the attacker.

Generated by OpenCVE AI on September 15, 2026 at 17:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the OpenstatusHQ installation to include the patch identified by commit 86f370c9c20074c3c3fdec53a359874b8e670fd4 (or any later commit containing the fix) and redeploy the service.
  • If the patch cannot be applied immediately, disable the custom domain rewrite feature or constrain its configuration to a whitelist of trusted domains to limit outbound HTTP traffic.
  • Configure the application’s outbound HTTP settings or the surrounding network firewall to block or restrict requests to internal or untrusted destinations, thereby preventing potential SSRF activity.

Generated by OpenCVE AI on September 15, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
Title openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery
First Time appeared Openstatushq
Openstatushq openstatus
Weaknesses CWE-918
CPEs cpe:2.3:a:openstatushq:openstatus:*:*:*:*:*:*:*:*
Vendors & Products Openstatushq
Openstatushq openstatus
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Openstatushq Openstatus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:11:39.250Z

Reserved: 2026-09-12T08:03:27.652Z

Link: CVE-2026-90486

cve-icon Vulnrichment

Updated: 2026-09-15T17:11:35.324Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T23:17:01.073

Modified: 2026-09-15T18:19:36.433

Link: CVE-2026-90486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)