SB2026072844 - Server-Side Request Forgery (SSRF) in Dify



SB2026072844 - Server-Side Request Forgery (SSRF) in Dify

Published: July 28, 2026

Security Bulletin ID SB2026072844
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.

The vulnerability exists due to server-side request forgery in the /console/api/remote-files/upload endpoint when handling a user-supplied url parameter. A remote attacker can send a specially crafted request to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.

Cloud metadata endpoints and otherwise inaccessible internal services may be reachable through the vulnerable server.


Remediation

Install update from vendor's website.