Description
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, or other restricted network resources, potentially enabling interaction with internal services or cloud metadata endpoints from the server's network context.
Published: 2026-05-28
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FlowIntel versions up to 3.3.0 contain a server‑side request forgery (SSRF) flaw in the external reference URL probe implemented in app/case/task.py. An attacker who can supply an external reference URL can cause the application server to send an HTTP HEAD request to the attacker‑specified destination. Because the application performs insufficient validation of the URL scheme and of the resolved destination address, the server may request resources on loopback, link‑local, private, reserved, or otherwise restricted network addresses. This opens the possibility of the server accessing internal services or cloud metadata endpoints that would normally be out of reach from the outside world.

Affected Systems

The vulnerability affects deployments of the FlowIntel product whose version is 3.3.0 or earlier. Any installation that still uses the default external reference URL probe without applying the vendor's fix is thus susceptible to exploitation.

Risk and Exploitability

The CVSS score for this flaw is 6.2 and it is not listed in the CISA KEV catalog. EPSS information is unavailable. Based on the description, it is inferred that the attack vector is remote and occurs via the web interface where an attacker can submit a crafted URL. If the application is exposed to untrusted users, the likelihood of exploitation is elevated, because the attacker does not need elevated privileges on the server. The flaw enables the server to reach internal network resources, which could allow reconnaissance of internal services or acquisition of cloud metadata, depending on the target environment’s network segmentation.

Generated by OpenCVE AI on May 28, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FlowIntel to the latest release that contains the SSRF fix.
  • Modify the application configuration or code to reject URLs that target loopback, link‑local, private, or reserved addresses, or that use non‑HTTP schemes.
  • Restrict outbound network traffic from the FlowIntel server via firewall rules or proxy settings so that it cannot reach internal services or cloud metadata endpoints.
  • Monitor outgoing HTTP HEAD requests for unexpected access to internal resources and investigate any anomalies.

Generated by OpenCVE AI on May 28, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Flowintel
Flowintel flowintel
Vendors & Products Flowintel
Flowintel flowintel

Thu, 28 May 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 10:15:00 +0000

Type Values Removed Values Added
Description FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, or other restricted network resources, potentially enabling interaction with internal services or cloud metadata endpoints from the server's network context.
Title FlowIntel external reference URL probe allows server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 6.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:H/SA:H/S:N/RE:L/U:Green'}


Subscriptions

Flowintel Flowintel
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-05-28T10:31:00.608Z

Reserved: 2026-05-28T09:25:37.499Z

Link: CVE-2026-9813

cve-icon Vulnrichment

Updated: 2026-05-28T10:30:55.766Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T10:16:40.243

Modified: 2026-05-29T14:46:09.837

Link: CVE-2026-9813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T21:19:15Z

Weaknesses