Description
Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks and cloud metadata services.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SSRF via clientAddress parameter
Action: Apply Patch
AI Analysis

Impact

Hippo4j through version 1.5.0 implements four ThreadPoolController endpoints that do not validate the clientAddress argument supplied by authenticated callers. The flaw allows an attacker who can authenticate to the application to cause the server to issue outbound HTTP GET requests to arbitrary hostnames and ports. This type of server‑side request forgery can expose internal resources, permit enumeration of the internal network, or retrieve cloud provider metadata services, potentially revealing sensitive configuration or credentials. The vulnerability is categorized as CWE‑918.

Affected Systems

The affected product is Hippo4j, maintained by Opengoofy, in all releases up to and including 1.5.0. The flaw resides in the ThreadPoolController in both the hippo4j-auth and hippo4j-console modules. Users running any version of Hippo4j before 1.5.0 that exposes these endpoints and allows authenticated access are vulnerable.

Risk and Exploitability

The Common Vulnerability Scoring System assigns a score of 5.3, indicating a medium‑level impact. The Exploit Prediction Scoring System shows an exploitation probability of less than 1 %, reflecting the need for valid credentials and specific endpoint access, reducing the likelihood of widespread abuse. Hippo4j is not listed in the CISA Known Exploited Vulnerabilities catalog. The flaw is exploitable from an authenticated context on any host where the application is reachable; attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks or cloud metadata services.

Generated by OpenCVE AI on September 18, 2026 at 05:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hippo4j to a version that fixes the SSRF flaw or apply an available patch from the vendor
  • If an upgrade is not possible, restrict or disable the clientAddress endpoint by removing it or adding validation to ensure the target is on an allowed list
  • Configure outbound network filtering or a firewall to block the application from making HTTP requests to internal addresses or public cloud metadata URLs

Generated by OpenCVE AI on September 18, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks and cloud metadata services.
Title Hippo4j through 1.5.0 SSRF via clientAddress Parameter
First Time appeared Opengoofy
Opengoofy hippo4j
Weaknesses CWE-918
CPEs cpe:2.3:a:opengoofy:hippo4j:*:*:*:*:*:*:*:*
Vendors & Products Opengoofy
Opengoofy hippo4j
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Opengoofy Hippo4j
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:42.767Z

Reserved: 2026-09-16T13:34:45.540Z

Link: CVE-2026-92569

cve-icon Vulnrichment

Updated: 2026-09-21T16:03:49.873Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:02.593

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)