Server-side Request Forgery in Hippo4j Affects Cloud Metadata Services
CVE-2026-92569
5.3MEDIUM
What is CVE-2026-92569?
Hippo4j version 1.5.0 contains a server-side request forgery vulnerability affecting four endpoints within the ThreadPoolController. This flaw arises from inadequate validation of the clientAddress parameter, allowing authenticated attackers to supply arbitrary hostnames and ports. By doing so, they can trigger outbound GET requests, potentially exposing internal network services and sensitive cloud metadata. Proper mitigation strategies are essential to safeguard these endpoints.
Affected Version(s)
hippo4j 0 <= 1.5.0
