Server-Side Request Forgery in OpenViking Affects Multiple Internal Services
CVE-2026-22681

8.3HIGH

Key Information:

Vendor

Volcengine

Vendor
CVE Published:
21 August 2026

What is CVE-2026-22681?

OpenViking versions prior to 0.3.4 are vulnerable to a server-side request forgery (SSRF) flaw that permits authenticated low-privilege users to exploit the resources API endpoint. By submitting specially crafted URLs, attackers can cause the server to perform outbound requests to sensitive internal services, including loopback addresses, private IP ranges, and cloud metadata APIs. This vulnerability allows attackers to interact with and enumerate internal network resources, amplifying the potential impact on system security.

Affected Version(s)

OpenViking 0 < 0.3.4

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.