Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 21, 2026
Sipeed PicoClaw web.go web_fetch server-side request forgery
CVE-2026-16084
Description
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: c15aac21fe05ee103a470e1104bc891754e83392. To fix this issue, it is recommended to deploy a patch.
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/sipeed/picoclaw/commit/c15aac21fe05ee103a470e1104bc891754e83392mitrepatch
- github.com/sipeed/picoclaw/pull/3143mitreissue-trackingpatch
- github.com/sipeed/picoclaw/issues/3074mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-16084mitrethird-party-advisory
- vuldb.com/submit/852946mitrethird-party-advisory
- vuldb.com/vuln/379796mitrevdb-entrytechnical-description
- vuldb.com/vuln/379796/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.