Description
A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-24
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch ASAP
AI Analysis

Impact

The flaw lies in the chat-server component of songxinjianqwe Chat, where an attacker can craft requests that cause the server to reach arbitrary URLs. This server‑side request forgery can be triggered remotely and may expose internal network resources, sensitive data, or enable further attacks. The weakness is classified as CWE‑918 and is considered a high‑severity vulnerability with a CVSS score of 6.9.

Affected Systems

The affected product is songxinjianqwe Chat, specifically the chat-server module up to commit ac63d25297079eed5e4ba7e88d3b7a032637150d. The product follows a rolling release model, so specific affected versions are not listed but any release before the mentioned commit is potentially vulnerable.

Risk and Exploitability

A publicly available exploit is known, and the attack can be initiated from a remote location. The CVSS score of 6.9 indicates moderate to high risk, while the lack of EPSS data suggests uncertainty about current exploitation frequency. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack and SSRF potential necessitate immediate action.

Generated by OpenCVE AI on September 25, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update songxinjianqwe Chat to the latest release that contains the SSRF fix
  • Configure network controls (firewalls or proxy) to restrict outbound requests from the Chat server to only approved endpoints
  • Monitor server logs for unexpected outbound traffic and investigate anomalies promptly

Generated by OpenCVE AI on September 25, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Title songxinjianqwe Chat chat-server ChatServer.java server-side request forgery
First Time appeared Songxinjianqwe
Songxinjianqwe chat
Weaknesses CWE-918
CPEs cpe:2.3:a:songxinjianqwe:chat:*:*:*:*:*:*:*:*
Vendors & Products Songxinjianqwe
Songxinjianqwe chat
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Songxinjianqwe Chat
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-24T19:45:14.643Z

Reserved: 2026-09-24T11:38:22.602Z

Link: CVE-2026-97326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:35.907

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-97326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T06:15:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)