Server-Side Request Forgery (SSRF) in Apache CloudStack - CVE-2026-61422

 

Server-Side Request Forgery (SSRF) in Apache CloudStack - CVE-2026-61422

Published: August 24, 2026


Vulnerability identifier: #VU144656
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61422
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to trigger server-side requests to unintended destinations.

The vulnerability exists due to server-side request forgery in the template and ISO registration functionality when registering a template or ISO before URL validation is performed. A remote user can submit a crafted registration request to trigger server-side requests to unintended destinations.

The server makes a live HTTP HEAD or GET request for file size checks before validating the URL, but URL validation still occurs before the actual download by the Secondary Storage VM.


Affected software

Apache CloudStack

How to mitigate CVE-2026-61422

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins