Server-Side Request Forgery in 9Router by Decolua
CVE-2026-63313

8.3HIGH

Key Information:

Vendor

Decolua

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-63313?

9Router versions before 0.4.72 are susceptible to a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. This issue arises when the endpoint processes a user-controlled URL parameter and forwards it to an external scraping provider. The lack of a robust blocklist allows for potential exploitation, enabling authenticated or locally-connected users to compel the server to fetch internal URLs. This allows unauthorized access to sensitive information, such as cloud metadata credentials, and the capability to interact with internal services, potentially undermining security measures in place.

Affected Version(s)

9router 0 < 0.4.72

9router 0.4.72

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.