Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy
Published Oct 1, 2026
7.6
HIGHCVSS 3.1
EPSS 0.32%
Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.
Affected products
-
- Version < 1.0.8.6StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.32% (0.00315) | 22.18th | v5 (v2026.06.15) |
| Oct 2, 2026 | 0.32% (0.00315) | 22.15th | v5 (v2026.06.15) |
References (3)
- https://github.com/givanz/Vvveb/commit/e27d1ef097a8502c33f8cc94271c948407c5dce3 x_refsource_MISC
- https://github.com/givanz/Vvveb/releases/tag/1.0.8.6 x_refsource_MISC
- https://github.com/givanz/Vvveb/security/advisories/GHSA-r6g4-5m3x-xrqj x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/givanz/Vvveb/commit/e27d1ef097a8502c33f8cc94271c948407c5dce3 | x_refsource_MISC | |
| https://github.com/givanz/Vvveb/releases/tag/1.0.8.6 | x_refsource_MISC | |
| https://github.com/givanz/Vvveb/security/advisories/GHSA-r6g4-5m3x-xrqj | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.