Server-Side Request Forgery Vulnerability in Jina AI Reader
CVE-2026-82638

8.7HIGH

Key Information:

Vendor

Jina-ai

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82638?

The Jina AI Reader has a vulnerability that disables its private-address guard when deployed outside Google Cloud environments. This flaw allows unauthenticated attackers to execute server-side request forgery (SSRF) attacks. By exploiting this vulnerability, attackers can supply publicly resolvable hostnames that lead to private addresses, potentially revealing sensitive cloud metadata and internal service content. Organizations utilizing Jina AI Reader should be aware of this risk and take appropriate measures to secure their deployments.

Affected Version(s)

reader 45d1682db02f0c50b680ad350855da4e38ab2122 <= 1574bfd380d249c86c82db4dace0d9c8fe17e2b1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.