PT-2026-36584 · Unknown · Jeecg-Boot

Ana10Gy

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-7605

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JeecgBoot versions prior to 3.9.2
Description A flaw in the uploadImgByHttpEndpoint component allows for remote server-side request forgery (SSRF), which occurs when a server is tricked into making unauthorized requests to internal or external resources. This issue affects the functions CommonController.uploadImgByHttp(), HttpFileToMultipartFileUtil.httpFileToMultipartFile(), and HttpFileToMultipartFileUtil.downloadImageData() within the CommonController.java file.
Recommendations Upgrade to the upcoming release containing the fix. As a temporary workaround, restrict access to the CommonController.uploadImgByHttp() function to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7605

Affected Products

Jeecg-Boot