Server-Side Request Forgery (SSRF) in Apache CloudStack - CVE-2026-61422
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to trigger server-side requests to unintended destinations.
The vulnerability exists due to server-side request forgery in the template and ISO registration functionality when registering a template or ISO before URL validation is performed. A remote user can submit a crafted registration request to trigger server-side requests to unintended destinations.
The server makes a live HTTP HEAD or GET request for file size checks before validating the URL, but URL validation still occurs before the actual download by the Secondary Storage VM.