SB2026072844 - Server-Side Request Forgery (SSRF) in Dify
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.
The vulnerability exists due to server-side request forgery in the /console/api/remote-files/upload endpoint when handling a user-supplied url parameter. A remote attacker can send a specially crafted request to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.
Cloud metadata endpoints and otherwise inaccessible internal services may be reachable through the vulnerable server.
Remediation
Install update from vendor's website.