PT-2026-96158 · Drawio · Drawio

CVE-2026-63334

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions draw.io versions prior to 30.2.7
Description Deployments with ENABLE DRAWIO PROXY=1 are susceptible to server-side request forgery. This occurs because the Utils.sanitizeUrl() function in src/main/java/com/mxgraph/online/Utils.java performs a private-address check using one DNS resolution, while src/main/java/com/mxgraph/online/ProxyServlet.java subsequently calls URL.openConnection() and performs a second resolution. An attacker can use a hostname that resolves to a public address during the initial validation and then resolves to a private, link-local, or cloud metadata address when the connection is established. This can allow the retrieval of cloud instance metadata or responses from internal HTTP services via the proxy.
Recommendations Update to version 30.2.7. As a temporary mitigation, set ENABLE DRAWIO PROXY=0 to disable the proxy functionality.

Exploit

Fix

Time Of Check To Time Of Use

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63334
GHSA-3V4H-8R2C-M8C5

Affected Products

Drawio