Server-Side Request Forgery in Privoce VoceChat Server
Privoce VoceChat Server versions up to 0.5.36 are vulnerable to server-side request forgery via the open_graphic_parse endpoint, allowing remote attackers to perform unauthorized outbound requests.
CVE search metadata
CVE search record: CVE-2026-100893. Severity: high. CVSS: 7.3. KEV: no. Product: VoceChat Server (<= 0.5.36). Brief: Server-Side Request Forgery in Privoce VoceChat Server. Brief link: https://feed.craftedsignal.io/briefs/2026-09-vocechat-ssrf/
Privoce VoceChat Server up to version 0.5.36 contains a server-side request forgery (SSRF) vulnerability. The flaw exists within the open_graph::fetch function located in the src/api/resource.rs file, which powers the open_graphic_parse endpoint. An unauthenticated remote attacker can manipulate the url argument processed by this function to force the server to initiate unauthorized HTTP requests to arbitrary internal or external destinations. This vulnerability has been publicly disclosed, and exploitation is possible. As the vendor has not provided a response or a patch for this issue, defenders must assume the risk of exploitation remains for all instances running version 0.5.36 or earlier.
Impact
Successful exploitation allows a remote attacker to bypass network perimeter defenses by leveraging the server as a proxy. This can lead to unauthorized access to internal services not exposed to the internet, exfiltration of cloud metadata (if hosted in AWS/GCP/Azure environments), or reconnaissance of private network architecture. The vulnerability carries a CVSS v3.1 base score of 7.3, reflecting its potential for significant impact on service integrity and network confidentiality.
Recommendation
- Implement network egress filtering on all servers running VoceChat to prevent unauthorized outbound requests to sensitive internal network ranges or non-essential external endpoints.
- Monitor web server access logs for anomalous requests to the open_graphic_parse endpoint, specifically looking for unusual URL parameter values or unexpected destination hostnames.
- Due to the lack of a vendor-provided patch, consider placing the VoceChat instance behind a Web Application Firewall (WAF) and configure rules to inspect and restrict the 'url' parameter passed to the open_graphic_parse endpoint.
- If the application functionality is not critical, disable the open_graphic_parse endpoint entirely.
Immediate actions
Review egress traffic from VoceChat server instances for internal network scanning
Mitigations
Restrict outbound network connectivity for VoceChat server via host-based firewall
CVE-2026-100893
Detection coverage 1
Detect CVE-2026-100893 Exploitation - SSRF in VoceChat open_graphic_parse
highDetects potential exploitation of CVE-2026-100893 by monitoring for POST requests to the open_graphic_parse endpoint containing URL schemes pointing to internal network segments or local loopback addresses.
Detection queries are available on the platform. Get full rules →