Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.
Published May 26, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.36%
Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.
For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Affected products
-
- Version 0StatusaffectedConstraints<1.14.4
- Version 0StatusaffectedConstraints<1.15.2
- Version 0StatusaffectedConstraints<1.16.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Google Cloud | Apigee-X | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release 1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 .
For Apigee Hybrid: you must upgrade to one of the following security patch releases:
* for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1
References (2)
Change history (0)
No recorded changes yet.