Unrated severityOSV Advisory· Published Jan 7, 2026· Updated Jan 7, 2026
Knowage is vulnerable to blind server-side request forgery (SSRF)
CVE-2025-58441
Description
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
Affected products
1- Range: v7.0.0-RC, v7.2.0, v7.2.0-2020-04-06, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-m6x8-wh9v-6jxpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.