PT-2026-25009 · Opencti · Opencti

Daffyspider

·

Publicado

2026-03-12

·

Atualizado

2026-03-12

·

CVE-2026-21887

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 6.8.16
Description OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. The platform’s data ingestion feature accepts user-supplied URLs without validation and utilizes the Axios HTTP client with its default configuration (allowAbsoluteUrls: true). This allows attackers to construct requests to arbitrary endpoints, including internal services, as Axios accepts and processes absolute URLs. This results in a semi-blind Server-Side Request Forgery (SSRF), where responses may not be fully visible but can still impact internal systems. The API endpoint involved in this issue is the data ingestion feature, which accepts URLs via the URL parameter.
Recommendations Versions prior to 6.8.16 should be updated to version 6.8.16 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21887
GHSA-FFM6-VVPH-G5F5
PYSEC-2026-118

Produtos afetados

Opencti