Back

LOW

keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding

Published Aug 19, 2026

Description

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses by exploiting a DNS rebinding attack against the two-phase URL validation and connection flow. The SSRF guard validates a hostname's resolved IP addresses but discards them before the actual HTTP connection is opened, allowing an attacker who controls authoritative DNS to return a public address during validation and a private address during the subsequent independent socket-level DNS resolution, causing the guard to pass while the outbound connection reaches internal infrastructure such as cloud instance metadata endpoints.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 17, 2026
CISA Vulnrichment
Updated Aug 19, 2026
NVD
Status Received
Modified Aug 19, 2026
Red Hat
Severity n/a
Public date n/a