Server-Side Request Forgery in 9Router by Decolua
CVE-2026-63313
8.3HIGH
What is CVE-2026-63313?
9Router versions before 0.4.72 are susceptible to a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. This issue arises when the endpoint processes a user-controlled URL parameter and forwards it to an external scraping provider. The lack of a robust blocklist allows for potential exploitation, enabling authenticated or locally-connected users to compel the server to fetch internal URLs. This allows unauthorized access to sensitive information, such as cloud metadata credentials, and the capability to interact with internal services, potentially undermining security measures in place.
Affected Version(s)
9router 0 < 0.4.72
9router 0.4.72
