Back

MEDIUM

Huly Platform through 0.7.426 SSRF via Print Service

Published Sep 14, 2026

Description

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 14, 2026
Updated Sep 24, 2026
Reserved Sep 14, 2026
CISA Vulnrichment
Updated Sep 14, 2026
NVD
Status Received
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a