PT-2026-96711 · Tauri · Tauri-Plugin-Http

·

CVE-2026-95623

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.6

Medium

VectorAV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tauri HTTP plugin (affected versions not specified)
Description The HTTP plugin validates requested URLs against the application's configured scope allowlist only during the initial request. If the remote server returns an HTTP 3xx redirect, the internal reqwest library follows the redirect without re-validating the new target URL against the scope. This behavior enables an attacker who controls an allowed URL, or leverages an open redirect on an allowed host, to access restricted destinations, including localhost services, internal network hosts, or cloud metadata endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95623
GHSA-2RXP-F4W5-6HJR

Affected Products

Tauri-Plugin-Http