CVE-2026-86539

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 23:16

Updated : 2026-09-09 15:17


NVD link : CVE-2026-86539

Mitre link : CVE-2026-86539

CVE.ORG link : CVE-2026-86539


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)