← Back

CVE-2026-65924

nvd nist
Published: Jul 27, 2026Modified: Jul 30, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: reefs@jfrog.com (Secondary)

Description

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.

Affected (6)

Products: Jfrog: Artifactory
1 product
Artifactory
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Jfrog
Before 7.111.18
From 7.117.0 to 7.117.25
From 7.125.0 to 7.125.18
From 7.133.0 to 7.133.27
From 7.146.0 to 7.146.34
From 7.161.0 to 7.161.15

References (2)

Timeline

No history available yet.