PT-2026-79327 · Apache · Cloudstack

·

CVE-2026-61422

·

Published

2026-08-21

·

Updated

2026-08-27

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache CloudStack version 4.20.3.0 Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description An authenticated Server-Side Request Forgery (SSRF) exists in the template and ISO registration functionality. When registering a template or ISO, the system performs a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks before URL validation is executed. This does not allow for malicious template or ISO registration because URL validation is still performed before the Secondary Storage VM initiates the actual download.
Recommendations Upgrade version 4.20.3.0 to 4.20.3.1 or later. Upgrade versions 4.21.0.0 through 4.22.1.0 to 4.22.1.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61422

Affected Products

Cloudstack