No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Graylog2
Graylog2 graylog2-server |
|
| Vendors & Products |
Graylog2
Graylog2 graylog2-server |
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services, enabling the server to fetch and return internal responses. | |
| Title | Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T19:24:45.903Z
Reserved: 2026-09-16T19:31:53.122Z
Link: CVE-2026-92789
Updated: 2026-09-17T19:17:00.499Z
Status : Deferred
Published: 2026-09-16T21:17:28.330
Modified: 2026-09-22T20:53:07.383
Link: CVE-2026-92789
No data.
OpenCVE Enrichment
Updated: 2026-09-18T07:15:04Z