Back to overview

CVE-2026-56771

HIGH
8.5
CVSS 3.1
Description
NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.

Metadata

CVE ID
CVE-2026-56771
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-23 01:22 UTC
Published
2026-06-25 18:07 UTC
Last updated
2026-06-25 18:07 UTC
Primary CWE
CWE-918
Server-Side Request Forgery (SSRF)
Vendor / Product
samuelclay / NewsBlur
Sources
cve.org  ·  NVD

Severity & Metrics

8.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
samuelclay NewsBlur 0 < 14.5.0
Weakness (CWE)
CWESourceDescription
CWE-918 cna Server-Side Request Forgery (SSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N
Back to overview