SSRF
appsec.fyi
CiberInteligencia Chile: NEXT.JS CRÍTICO: CVE-2026-44578 (SSRF) Falla en WebSocket robo de credenciales cloud API keys y acceso a paneles internos Afecta self-hosted. Actualiza para evitar explotación #Nextjs #SSRF #CVE #Ciberseguridad
2026-05-17
xHackInSeconds: URL field accepted internal addresses. 169.254.169.254. IAM role credentials in the response. Full S3 and RDS access. #infosec #cloud #ssrf
2026-05-17
White Rabbitx : CVE-2026-7221 A vulnerability in TencentCloudBase CloudBaseMCP up to 2.17.0 affects openUrl; manipulating req.body.url can lead to remote SSRF. #CVE-2026-7221 #CloudBaseMCP #SSRF #Vulnerability #CWE918 nvd.nist.gov/vuln/detail/CVE
2026-05-17
Rasputin.DZ: got my first "exceptional technical depth" on a duplicate report half compliment half punishment. building my way up one dupe at a time. The grind continues. #bugbounty #infosec #SSRF #OWASP #WebAppSec #APIsecurity #CloudSecurity #GCP
2026-05-15
Critical Next.js Vulnerability Exposes Cloud Credentials API keys and Admin Panels
2026-05-15
More SSRF →