HIGH
Chartbrew has SSRF in API Data Connection - No IP Validation on User-Provided URLs
Published Apr 10, 2026
7.8
HIGHCVSS 4.0
EPSS 0.40%
Description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP address validation, enabling Server-Side Request Forgery attacks against internal networks and cloud metadata endpoints. This vulnerability is fixed in 4.8.5.
Affected products
-
- Version < 4.8.5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/chartbrew/chartbrew/commit/9c4a7e2b02acb25f0782bd4ac1f16407d59c2df1 x_refsource_MISCPatch
- https://github.com/chartbrew/chartbrew/security/advisories/GHSA-p4rg-967r-w4cv x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/chartbrew/chartbrew/commit/9c4a7e2b02acb25f0782bd4ac1f16407d59c2df1 | x_refsource_MISCPatch | |
| https://github.com/chartbrew/chartbrew/security/advisories/GHSA-p4rg-967r-w4cv | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 10, 2026
Updated Apr 15, 2026
Reserved Mar 4, 2026
Link CVE-2026-30232
CISA Vulnrichment
Updated Apr 15, 2026