MEDIUM
Huly Platform through 0.7.426 SSRF via Print Service
Published Sep 14, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.37%
Description
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.
Affected products
-
- Version 0StatusaffectedConstraints<=0.7.426
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hcengineering | Platform | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/hcengineering/platform product
- https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/config.ts technical-description
- https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/server.ts technical-description
- https://github.com/hcengineering/platform/issues/10908 issue-tracking
- https://www.vulncheck.com/advisories/huly-platform-through-0.7.426-ssrf-via-print-service third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/hcengineering/platform | product | |
| https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/config.ts | technical-description | |
| https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/server.ts | technical-description | |
| https://github.com/hcengineering/platform/issues/10908 | issue-tracking | |
| https://www.vulncheck.com/advisories/huly-platform-through-0.7.426-ssrf-via-print-service | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 14, 2026
Updated Sep 24, 2026
Reserved Sep 14, 2026
Link CVE-2026-91079
CISA Vulnrichment
Updated Sep 14, 2026