CVE-2026-86539 - knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
CVE ID :CVE-2026-86539
Published : Sept. 7, 2026, 11:16 p.m. | 1 hour, 48 minutes ago
Description :knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 7, 2026, 11:16 p.m. | 1 hour, 48 minutes ago
Description :knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...