VYPR
Vendor

Jina AI

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-85699HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata…

  • CVE-2026-82638HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.00

    jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal…

  • CVE-2026-18647HigAug 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to…