Medium severity4.3NVD Advisory· Published Sep 16, 2026
CVE-2026-92569
CVE-2026-92569
Description
Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks and cloud metadata services.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/opengoofy/hippo4j/blob/73124de92e269940bdf44f4534b37a13a36ffd49/hippo4j-server/hippo4j-auth/src/main/java/cn/hippo4j/auth/config/GlobalSecurityConfig.javanvd
- github.com/opengoofy/hippo4j/blob/73124de92e269940bdf44f4534b37a13a36ffd49/hippo4j-server/hippo4j-console/src/main/java/cn/hippo4j/console/controller/ThreadPoolController.javanvd
- github.com/opengoofy/hippo4j/issues/1621nvd
- www.vulncheck.com/advisories/hippo4j-through-1.5.0-ssrf-via-clientaddress-parameternvd
News mentions
0No linked articles in our index yet.