Server-Side Request Forgery (SSRF) in JFrog Artifactory - CVE-2026-70548
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to perform server-side requests to remote CocoaPods repositories.
The vulnerability exists due to server-side request forgery in JFrog Artifactory External Dependency for CocoaPods when processing external dependency requests. A remote user can trigger requests to remote CocoaPods repositories to perform server-side requests to remote CocoaPods repositories.
Exploitation is possible only under specific circumstances.