Server-Side Request Forgery (SSRF) in Artifactory - CVE-2026-65618
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to initiate unauthorized requests from the server and disclose cached response data.
The vulnerability exists due to server-side request forgery in URL handling when processing specific URLs. A remote attacker can supply a specially crafted URL to initiate unauthorized requests from the server and disclose cached response data.
Internal services may be exposed through server-originated requests.