High severity8.6NVD Advisory· Published Jun 22, 2026· Updated Jun 30, 2026
CVE-2026-56266
CVE-2026-56266
Description
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
crawl4aiPyPI | < 0.8.7 | 0.8.7 |
Affected products
2Patches
Vulnerability mechanics
References
21- github.com/advisories/GHSA-365w-hqf6-vxfgghsaADVISORY
- github.com/advisories/GHSA-53rg-46cm-4g2vghsaADVISORY
- github.com/advisories/GHSA-8qrg-7j2f-rf2hghsaADVISORY
- github.com/advisories/GHSA-g2pv-76hm-j4x9ghsaADVISORY
- github.com/advisories/GHSA-xrfj-6m49-wfmmghsaADVISORY
- github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfgnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-56266ghsaADVISORY
- www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-direct-crawl-endpointsnvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-229.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-230.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-239.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3443.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3449.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-596.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-798.yamlghsaWEB
- www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameterghsaWEB
- www.vulncheck.com/advisories/crawl4ai-arbitrary-javascript-execution-via-execute-js-endpointghsaWEB
- www.vulncheck.com/advisories/crawl4ai-authentication-bypass-via-hardcoded-jwt-signing-keyghsaWEB
- www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-webhook-urlsghsaWEB
- www.vulncheck.com/advisories/crawl4ai-stored-cross-site-scripting-in-monitor-dashboardghsaWEB
- www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-endpoints-via-docker-api-serverghsaWEB
News mentions
1- Unclecode Crawl4AI: Five CVEs Disclosed Together Reveal Auth Bypass, SSRF, and XSS FlawsVypr Intelligence · Jun 24, 2026