Server-Side Request Forgery Vulnerability in Vulnerability-Lookup by Vulnerability-Lookup
CVE-2026-73432

5.1MEDIUM

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73432?

The Vulnerability-Lookup platform contains a server-side request forgery vulnerability due to improper validation of remote instance addresses during synchronization. An authenticated administrator with the appropriate permissions may configure a remote instance pointing to sensitive internal services. This flaw allows an attacker to exploit the synchronization routine, probing services that the attacker cannot directly access. Exploiting this vulnerability could unlock access to private network services or cloud metadata endpoints, which should remain secure. The recent patch introduces tighter security measures, including restrictions to HTTP(S) traffic, rejecting non-public IP addresses, and enhanced validation of redirect destinations.

Affected Version(s)

vulnerability-lookup 0 <= 5.5.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

openai/gpt-5.5-cyber-preview (reasoning level: high)
EUVD @ ENISA Team
Cedric Bonhomme
Alexandre Dulaunoy
.