SB2026090756 - Server-Side Request Forgery (SSRF) in draw.io



SB2026090756 - Server-Side Request Forgery (SSRF) in draw.io

Published: September 7, 2026

Security Bulletin ID SB2026090756
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information from internal services.

The vulnerability exists due to improper restriction of server-side request forgery in the validatedAddress() method when processing URLs containing IPv6 transition addresses. A remote attacker can send a crafted request to the embed or proxy endpoint to disclose sensitive information from internal services.

The embed endpoint is always enabled, while exploitation through the proxy endpoint requires the proxy feature to be enabled.


Remediation

Install update from vendor's website.