PT-2026-83867 · Qd · Qd
CVE-2026-51152
·
Published
2026-08-31
·
Updated
2026-09-01
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
QD versions 20220208 through 20250803
Description
An unauthenticated remote attacker can perform a Server-side request forgery (SSRF) via the '/har/test' endpoint. The
Fetcher.build request() function in libs/fetcher.py creates an httpclient.HTTPRequest using user-supplied JSON without validating the URL scheme, host, or IP range. Additionally, the validate cert variable is set to False, which disables TLS verification. This allows attackers to force the server to send arbitrary HTTP requests to cloud metadata endpoints and internal network resources.Recommendations
For QD versions 20220208 through 20250803, restrict access to the '/har/test' endpoint or disable its use until a fix is available.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qd