Server-side Request Forgery in Hippo4j Affects Cloud Metadata Services
CVE-2026-92569

5.3MEDIUM

Key Information:

Vendor

Opengoofy

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92569?

Hippo4j version 1.5.0 contains a server-side request forgery vulnerability affecting four endpoints within the ThreadPoolController. This flaw arises from inadequate validation of the clientAddress parameter, allowing authenticated attackers to supply arbitrary hostnames and ports. By doing so, they can trigger outbound GET requests, potentially exposing internal network services and sensitive cloud metadata. Proper mitigation strategies are essential to safeguard these endpoints.

Affected Version(s)

hippo4j 0 <= 1.5.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.