PT-2026-83867 · Qd · Qd

CVE-2026-51152

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions QD versions 20220208 through 20250803
Description An unauthenticated remote attacker can perform a Server-side request forgery (SSRF) via the '/har/test' endpoint. The Fetcher.build request() function in libs/fetcher.py creates an httpclient.HTTPRequest using user-supplied JSON without validating the URL scheme, host, or IP range. Additionally, the validate cert variable is set to False, which disables TLS verification. This allows attackers to force the server to send arbitrary HTTP requests to cloud metadata endpoints and internal network resources.
Recommendations For QD versions 20220208 through 20250803, restrict access to the '/har/test' endpoint or disable its use until a fix is available.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51152

Affected Products

Qd