Medium severity6.5NVD Advisory· Published Jul 27, 2026· Updated Jul 30, 2026
CVE-2026-65618
CVE-2026-65618
Description
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*range: <7.133.6
Patches
Vulnerability mechanics
References
2- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease Notes
News mentions
1- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · Jul 28, 2026