PT-2026-79394 · Volcengine+1 · Openviking

CVE-2026-22681

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenViking versions prior to 0.3.4
Description Authenticated low-privilege attackers can access internal network services by submitting arbitrary URLs to the resources API endpoint. By sending a POST request with a crafted URL to the '/api/v1/resources' endpoint, the server issues outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918 (private IP address spaces), link-local, or cloud metadata addresses. The attacker can then read the responses through normal content APIs to enumerate and interact with internal services. This is a server-side request forgery (SSRF), which occurs when a server is tricked into making requests to an unintended location.
Recommendations Update OpenViking to version 0.3.4 or later. Avoid using the '/api/v1/resources' endpoint until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22681

Affected Products

Openviking