Server-Side Request Forgery in YesWiki Affects Cloud Metadata Access
CVE-2026-104458
8.3HIGH
What is CVE-2026-104458?
YesWiki prior to version 4.6.7 is susceptible to a server-side request forgery vulnerability in the validateKeyIdUrl() function. This flaw enables unauthenticated attackers to circumvent server-side request forgery (SSRF) protections by manipulating the Signature keyId. Through various IP address formats, such as 6to4, NAT64, or IPv4-compatible IPv6 addresses, attackers can target the public actor inbox route. This exploitation could lead to unauthorized access to sensitive cloud metadata, loopback services, or even internal hosts, thereby posing a serious risk to the integrity of affected systems.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
