PT-2026-96158 · Drawio · Drawio
CVE-2026-63334
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
draw.io versions prior to 30.2.7
Description
Deployments with
ENABLE DRAWIO PROXY=1 are susceptible to server-side request forgery. This occurs because the Utils.sanitizeUrl() function in src/main/java/com/mxgraph/online/Utils.java performs a private-address check using one DNS resolution, while src/main/java/com/mxgraph/online/ProxyServlet.java subsequently calls URL.openConnection() and performs a second resolution. An attacker can use a hostname that resolves to a public address during the initial validation and then resolves to a private, link-local, or cloud metadata address when the connection is established. This can allow the retrieval of cloud instance metadata or responses from internal HTTP services via the proxy.Recommendations
Update to version 30.2.7.
As a temporary mitigation, set
ENABLE DRAWIO PROXY=0 to disable the proxy functionality.Exploit
Fix
Time Of Check To Time Of Use
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drawio