Skip to main content

Server-Side Request Forgery (SSRF)

CVE-2026-42352

Severity High
Score 8.6/10

Summary

OGC API - Process execution requests can use the `subscriber` object to requests to internal HTTP services. The issue has been patched in master branch and made available as part of the 0.23.3 release. The patch disables any HTTP requests made to internal resources by default (unless explicitly defined in configuration by a new allow_internal_requests directive. This affects versions starting from 0.23.0 prior to 0.23.3.

  • LOW
  • NETWORK
  • NONE
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-918 - Server-Side Request Forgery (SSRF)

Server-side request forgery (SSRF) is a weakness that allows an attacker to send an arbitrary request, making it appear that the request was sent by the server. This request may bypass a firewall that would normally prevent direct access to the URL. The impact of this vulnerability can vary from unauthorized access to files and sensitive information to remote code execution.

References

Advisory Timeline

  • Published