Server-Side Request Forgery in OpenViking Affects Multiple Internal Services
CVE-2026-22681
8.3HIGH
What is CVE-2026-22681?
OpenViking versions prior to 0.3.4 are vulnerable to a server-side request forgery (SSRF) flaw that permits authenticated low-privilege users to exploit the resources API endpoint. By submitting specially crafted URLs, attackers can cause the server to perform outbound requests to sensitive internal services, including loopback addresses, private IP ranges, and cloud metadata APIs. This vulnerability allows attackers to interact with and enumerate internal network resources, amplifying the potential impact on system security.
Affected Version(s)
OpenViking 0 < 0.3.4
