SSRF Vulnerability in Open edX Platform Affecting User-Submitted URLs
CVE-2026-55421

6.8MEDIUM

Key Information:

Vendor

Openedx

Vendor
CVE Published:
2 September 2026

What is CVE-2026-55421?

The Open edX Platform, which facilitates the creation and delivery of online learning content, has a vulnerability that allows server-side request forgery (SSRF) through user-supplied file URLs. An attacker can exploit this flaw to manipulate server behavior by supplying malicious URLs, resulting in unauthorized access or data exfiltration. The vulnerability existed prior to commit 00b7c3c but has since been addressed. Notably, the flaw's exploitability arose from the lack of a fetch timeout and follow-redirection policy which enabled potential data leaks.

Affected Version(s)

openedx-platform < 00b7c3ce418b487c5696b064fc5033594b045e75

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.