Improper Input Validation in OpenCVE Notification System
CVE-2026-62282

6.5MEDIUM

Key Information:

Vendor

Opencve

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-62282?

OpenCVE, a vulnerability intelligence platform, has a security issue before version 3.0.0 in its notification testing for Webhook and Slack integrations. The vulnerability stems from insufficient validation of user-supplied HTTP or HTTPS destinations, allowing authenticated users who can configure notification channels to send requests to hosts accessible from the OpenCVE server. This includes sensitive internal network resources, localhost interfaces, link-local addresses, and cloud metadata services, which could disclose sensitive information from reachable HTTP services. The issue has been addressed and resolved in version 3.0.0.

Affected Version(s)

opencve < 3.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.