PT-2026-22237 · Psi Probe · Psi Probe

Ana10Gy

+1

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-3270

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSI Probe versions up to 5.3.0
Description A flaw exists in PSI Probe that allows for server-side request forgery. This issue stems from the lookup function within the Whois.java file, located in the psi-probe-core/src/main/java/psiprobe/tools component. The manipulation of this function can lead to unauthorized requests being made on the server. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed. The vendor was notified but did not provide a response.
Recommendations Versions prior to 5.3.0 should be used.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-3270
GHSA-429M-9874-RX9W

Affected Products

Psi Probe