<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ssrf — PoC Archive</title><link>https://poc.intelseclab.com/tags/ssrf/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/ssrf/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</guid><description>High severity (CVSS 8.1) — cloud · CVE-2026-64640. Status: Patched. Affects: Apache Polaris (Apache Iceberg REST catalog), registerTable and registerView endpoints. Tags: apache-polaris, iceberg, apache-iceberg, credential-vending, confused-deputy, authorization-bypass, cross-tenant, s3, storage, allowed-locations, CWE-441, CWE-639, CWE-918, ssrf, server-side-read, information-disclosure, register-table, register-view.</description><category>cloud</category><category>High</category><category>apache-polaris</category><category>iceberg</category><category>apache-iceberg</category><category>credential-vending</category><category>confused-deputy</category><category>authorization-bypass</category><category>cross-tenant</category><category>s3</category><category>storage</category><category>allowed-locations</category><category>CWE-441</category><category>CWE-639</category><category>CWE-918</category><category>ssrf</category><category>server-side-read</category><category>information-disclosure</category><category>register-table</category><category>register-view</category></item><item><title>Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459). Status: Weaponized. Affects: Apache Tika - tika-parser-pdf-module (and legacy tika-parsers). Tags: apache-tika, xxe, xfa, pdf-parsing, cwe-611, ssrf, file-disclosure, tika-server.</description><category>web</category><category>Critical</category><category>apache-tika</category><category>xxe</category><category>xfa</category><category>pdf-parsing</category><category>cwe-611</category><category>ssrf</category><category>file-disclosure</category><category>tika-server</category></item><item><title>Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</guid><description>Critical severity (CVSS 9) — web · CVE-2026-16723. Status: PoC (no vendor patch, Fastjson 1.x line unpatched). Affects: Alibaba Fastjson (Java JSON library), packaged inside a Spring Boot executable fat-JAR. Tags: fastjson, deserialization, rce, java, spring-boot, autotype-bypass, jar-protocol, ssrf.</description><category>web</category><category>Critical</category><category>fastjson</category><category>deserialization</category><category>rce</category><category>java</category><category>spring-boot</category><category>autotype-bypass</category><category>jar-protocol</category><category>ssrf</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</link><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-15409 (SNWLID-2026-0008). Status: Weaponized — unauthenticated, non-root remote code execution confirmed against a real appliance build. Affects: SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service). Tags: sonicwall, sma1000, workplace, ssrf, erlang, rpc, cwe-918, unauthenticated, remote, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>sonicwall</category><category>sma1000</category><category>workplace</category><category>ssrf</category><category>erlang</category><category>rpc</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category></item><item><title>ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-34282. Status: Weaponized. Affects: ThingsBoard IoT Platform (Image Upload Gallery / Widget Library). Tags: thingsboard, ssrf, cwe-918, svg, image-upload, iot, python, widget-library, tenant-admin.</description><category>web</category><category>Critical</category><category>thingsboard</category><category>ssrf</category><category>cwe-918</category><category>svg</category><category>image-upload</category><category>iot</category><category>python</category><category>widget-library</category><category>tenant-admin</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-55315. Status: Weaponized. Affects: ASP.NET Core Kestrel web server (Microsoft.AspNetCore.Server.Kestrel). Tags: aspnet-core, kestrel, http-request-smuggling, chunked-transfer-encoding, dotnet, python, cwe-444, ssrf, cache-poisoning, webshell-upload.</description><category>network</category><category>Critical</category><category>aspnet-core</category><category>kestrel</category><category>http-request-smuggling</category><category>chunked-transfer-encoding</category><category>dotnet</category><category>python</category><category>cwe-444</category><category>ssrf</category><category>cache-poisoning</category><category>webshell-upload</category></item><item><title>Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-30065-parquet-avro-schema-deserialization-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-30065-parquet-avro-schema-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — misc · CVE-2025-30065. Status: PoC. Affects: Apache Parquet Java (parquet-avro module). Tags: rce, ssrf, unsafe-deserialization, parquet-avro, avro-schema, java-class, jvm, cwe-502, cwe-20, incomplete-fix, java.</description><category>misc</category><category>Critical</category><category>rce</category><category>ssrf</category><category>unsafe-deserialization</category><category>parquet-avro</category><category>avro-schema</category><category>java-class</category><category>jvm</category><category>cwe-502</category><category>cwe-20</category><category>incomplete-fix</category><category>java</category></item><item><title>WordPress User Language Switch Plugin SSRF — CVE-2026-0745</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</guid><description>Medium severity — web · CVE-2026-0745 (GHSA-m38c-5p3m-p7gm). Status: PoC. Affects: WordPress "User Language Switch" plugin. Tags: wordpress, ssrf, plugin-vulnerability, admin-ajax, cwe-918, metadata-endpoint.</description><category>web</category><category>Medium</category><category>wordpress</category><category>ssrf</category><category>plugin-vulnerability</category><category>admin-ajax</category><category>cwe-918</category><category>metadata-endpoint</category></item><item><title>Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35037-ech0-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35037-ech0-ssrf/</guid><description>High severity — web · CVE-2026-35037. Status: PoC. Affects: lin-snow/Ech0. Tags: ssrf, ech0, unauthenticated, self-hosted, cwe-918, nuclei-template.</description><category>web</category><category>High</category><category>ssrf</category><category>ech0</category><category>unauthenticated</category><category>self-hosted</category><category>cwe-918</category><category>nuclei-template</category></item><item><title>Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33712-typebot-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33712-typebot-ssrf/</guid><description>High severity — web · CVE-2026-33712. Status: PoC. Affects: Typebot (open-source chatbot builder), preview chat endpoint. Tags: ssrf, typebot, isolated-vm, sandbox-escape, cloud-metadata, node-js, unauthenticated, chatbot.</description><category>web</category><category>High</category><category>ssrf</category><category>typebot</category><category>isolated-vm</category><category>sandbox-escape</category><category>cloud-metadata</category><category>node-js</category><category>unauthenticated</category><category>chatbot</category></item><item><title>SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24423-smartermail-ssrf-connecttohub-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24423-smartermail-ssrf-connecttohub-rce/</guid><description>Critical severity — web · CVE-2026-24423. Status: PoC. Affects: SmarterMail (ConnectToHub / node clustering feature). Tags: ssrf, smartermail, connecttohub, unauthenticated, trust-boundary, rce, mail-server, node-management.</description><category>web</category><category>Critical</category><category>ssrf</category><category>smartermail</category><category>connecttohub</category><category>unauthenticated</category><category>trust-boundary</category><category>rce</category><category>mail-server</category><category>node-management</category></item><item><title>Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</guid><description>Critical severity (CVSS 9.3) — cloud · CVE-2026-32096. Status: PoC. Affects: Plunk (useplunk/plunk) email/webhook API. Tags: ssrf, aws-sns, imds, cloud-metadata, plunk, cwe-918, unauthenticated.</description><category>cloud</category><category>Critical</category><category>ssrf</category><category>aws-sns</category><category>imds</category><category>cloud-metadata</category><category>plunk</category><category>cwe-918</category><category>unauthenticated</category></item><item><title>pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</guid><description>High severity — web · CVE-2026-26801. Status: Weaponized. Affects: pdfmake (Node.js PDF generation library), src/URLResolver.js. Tags: ssrf, pdfmake, node-js, cloud-metadata, aws-imds, cwe-918, credential-theft, data-exfiltration.</description><category>web</category><category>High</category><category>ssrf</category><category>pdfmake</category><category>node-js</category><category>cloud-metadata</category><category>aws-imds</category><category>cwe-918</category><category>credential-theft</category><category>data-exfiltration</category></item><item><title>Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45401-ssrf-exploit/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45401-ssrf-exploit/</guid><description>High severity — web · CVE-2026-45401. Status: PoC. Affects: Open WebUI. Tags: ssrf, open-webui, redirect-bypass, url-validation-bypass, internal-network-access.</description><category>web</category><category>High</category><category>ssrf</category><category>open-webui</category><category>redirect-bypass</category><category>url-validation-bypass</category><category>internal-network-access</category></item><item><title>Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</guid><description>High severity — web · CVE-2026-45504. Status: PoC. Affects: Microsoft Exchange Server (OWA / EWS). Tags: exchange, owa, ews, file-read, ssrf, ntlm, soap, lfi.</description><category>web</category><category>High</category><category>exchange</category><category>owa</category><category>ews</category><category>file-read</category><category>ssrf</category><category>ntlm</category><category>soap</category><category>lfi</category></item><item><title>Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</guid><description>Critical severity — web · CVE-2026-49345. Status: PoC. Affects: Mercator (sourcentis/mercator vulnerability-management web app), ConfigurationController::testProvider. Tags: ssrf, redis, rce, gopher, webshell, internal-network-pivot, php, mercator.</description><category>web</category><category>Critical</category><category>ssrf</category><category>redis</category><category>rce</category><category>gopher</category><category>webshell</category><category>internal-network-pivot</category><category>php</category><category>mercator</category></item><item><title>MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42281-magicmirror-cors-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42281-magicmirror-cors-ssrf/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-42281. Status: PoC. Affects: MagicMirror². Tags: ssrf, unauthenticated, magicmirror, cloud-metadata, secrets-exfiltration, header-injection, open-proxy, python.</description><category>web</category><category>Critical</category><category>ssrf</category><category>unauthenticated</category><category>magicmirror</category><category>cloud-metadata</category><category>secrets-exfiltration</category><category>header-injection</category><category>open-proxy</category><category>python</category></item><item><title>LiteLLM /config/update Broken Access Control (CVE-2026-35029)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35029-litellm-config-broken-access-control/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35029-litellm-config-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-35029. Status: Weaponized. Affects: LiteLLM proxy. Tags: broken-access-control, litellm, ai-gateway, config-update, ssrf, rce, environment-variable-theft, cwe-863.</description><category>web</category><category>High</category><category>broken-access-control</category><category>litellm</category><category>ai-gateway</category><category>config-update</category><category>ssrf</category><category>rce</category><category>environment-variable-theft</category><category>cwe-863</category></item><item><title>Kan SSRF via Attachment Download Endpoint — CVE-2026-32255</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32255-kan-ssrf-attachment-download/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32255-kan-ssrf-attachment-download/</guid><description>High severity (CVSS 8.6) — web · CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg). Status: PoC. Affects: Kan (kanbn/kan) open-source project management tool. Tags: ssrf, kan, project-management, cwe-918, cloud-metadata, unauthenticated, full-read-ssrf.</description><category>web</category><category>High</category><category>ssrf</category><category>kan</category><category>project-management</category><category>cwe-918</category><category>cloud-metadata</category><category>unauthenticated</category><category>full-read-ssrf</category></item><item><title>EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</guid><description>Medium severity — web · CVE-2026-33534. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, ssrf, cwe-918, ipv4-obfuscation, authenticated, crm, file-upload, python.</description><category>web</category><category>Medium</category><category>espocrm</category><category>ssrf</category><category>cwe-918</category><category>ipv4-obfuscation</category><category>authenticated</category><category>crm</category><category>file-upload</category><category>python</category></item><item><title>Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33715-chamilo-lms-ssrf-mail-relay/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33715-chamilo-lms-ssrf-mail-relay/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-33715 / GHSA-mxc9-9335-45mc. Status: PoC. Affects: Chamilo LMS 2.0. Tags: ssrf, chamilo-lms, open-relay, unauthenticated, php, symfony-mailer, cwe-918, cwe-306, ajax-endpoint.</description><category>web</category><category>High</category><category>ssrf</category><category>chamilo-lms</category><category>open-relay</category><category>unauthenticated</category><category>php</category><category>symfony-mailer</category><category>cwe-918</category><category>cwe-306</category><category>ajax-endpoint</category></item><item><title>Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-40564-flink-k8s-operator-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-40564-flink-k8s-operator-ssrf/</guid><description>High severity — cloud · CVE-2026-40564. Status: PoC. Affects: Apache flink-kubernetes-operator. Tags: ssrf, kubernetes, flink, operator, kubernetes-operator, jarURI, cloud-metadata, crd.</description><category>cloud</category><category>High</category><category>ssrf</category><category>kubernetes</category><category>flink</category><category>operator</category><category>kubernetes-operator</category><category>jarURI</category><category>cloud-metadata</category><category>crd</category></item><item><title>@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</guid><description>High severity — web · CVE-2026-46391 (GHSA-4fg7-f244-3j49). Status: PoC. Affects: @haxtheweb/open-apis (HAXcms/HAX ecosystem web service APIs). Tags: haxtheweb, haxcms, open-apis, ssrf, cwe-918, credential-exposure, cacheaddress.</description><category>web</category><category>High</category><category>haxtheweb</category><category>haxcms</category><category>open-apis</category><category>ssrf</category><category>cwe-918</category><category>credential-exposure</category><category>cacheaddress</category></item><item><title>Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230. Status: Weaponized. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tags: SSRF, RCE, Cisco, Unified-Communications-Manager, WebDialer, file-write, webshell, jsp-webshell, CISA-KEV, active-exploitation.</description><category>network</category><category>Critical</category><category>SSRF</category><category>RCE</category><category>Cisco</category><category>Unified-Communications-Manager</category><category>WebDialer</category><category>file-write</category><category>webshell</category><category>jsp-webshell</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-websocket-upgrade-ssrf-self-hosted/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-websocket-upgrade-ssrf-self-hosted/</guid><description>High severity (CVSS 8.6) — web · CVE-2026-44578. Status: Weaponized. Affects: Next.js standalone router server (next start). Tags: SSRF, WebSocket, upgrade-request, Next.js, self-hosted, unauthenticated, metadata-service.</description><category>web</category><category>High</category><category>SSRF</category><category>WebSocket</category><category>upgrade-request</category><category>Next.js</category><category>self-hosted</category><category>unauthenticated</category><category>metadata-service</category></item><item><title>Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065)</title><link>https://poc.intelseclab.com/pocs/misc/2026-05-16_apache-parquet-unsafe-deserialization-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-05-16_apache-parquet-unsafe-deserialization-rce/</guid><description>Critical severity (CVSS 10) — misc · CVE-2025-30065. Status: Weaponized. Affects: Apache Parquet Java (parquet-avro) schema parsing consumers. Tags: RCE, unsafe-deserialization, parquet-avro, avro-schema, Java, JVM, SSRF, data-pipeline.</description><category>misc</category><category>Critical</category><category>RCE</category><category>unsafe-deserialization</category><category>parquet-avro</category><category>avro-schema</category><category>Java</category><category>JVM</category><category>SSRF</category><category>data-pipeline</category></item></channel></rss>