Server-Side Request Forgery (SSRF) in Webmin - #VU140703
Published: August 1, 2026
Webmin
Detailed vulnerability description
The vulnerability allows a remote user to access internal network resources and cloud metadata endpoints.
The vulnerability exists due to server-side request forgery (SSRF) in the Upload and Download and File Manager modules when downloading files from user-supplied URLs. A remote user can supply a crafted URL to access internal network resources and cloud metadata endpoints.
Only untrusted users with access to modules that can download files from other URLs are affected, and accessible targets must not be protected by authentication.