TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-5936

HIGH
8.5

Description

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

Details CVE

Score CVSS v3.18.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie4/13/2026
Derniere modification4/13/2026
Sourcenvd
Observations honeypot0

Faiblesses (CWE)

CWE-918

References

https://www.foxit.com/support/security-bulletins.html(14984358-7092-470d-8f34-ade47a7658a2)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.