SSRF Vulnerability in decolua 9Router
A server-side request forgery vulnerability in decolua 9Router versions up to 0.5.55 allows remote attackers to manipulate the provider_options.baseUrl argument to trigger unauthorized requests.
CVE search metadata
CVE search record: CVE-2026-103530. Severity: high. CVSS: 7.3. KEV: no. Product: 9Router (< 0.5.56). Brief: SSRF Vulnerability in decolua 9Router. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ssrf-decolua-9router/
CVE-2026-103530 identifies a server-side request forgery (SSRF) vulnerability affecting decolua 9Router in all versions up to and including 0.5.55. The vulnerability resides within the fetch function of the file src/shared/utils/ssrfGuard.js, which is part of the application's Search Endpoint component.
An attacker can exploit this flaw by remotely sending a crafted request that manipulates the provider_options.baseUrl argument. This manipulation forces the application to perform unauthorized requests to arbitrary internal or external resources, potentially leading to unauthorized data access, internal service discovery, or interaction with internal APIs that expect requests only from the trusted server environment. Impact is significant given the ability to bypass network segmentation by leveraging the server's context.
Impact
Successful exploitation allows remote attackers to perform SSRF attacks, potentially leading to unauthorized interaction with internal infrastructure, sensitive service exposure, or exfiltration of metadata from cloud instances or internal systems.
Recommendation
Upgrade 9Router to version 0.5.56 or later to apply the necessary security patch for the ssrfGuard.js component. Implement network egress filtering on the host running the 9Router service to restrict unauthorized outbound connections to internal segments.
Immediate actions
Upgrade 9Router to version 0.5.56
Mitigations
Restrict outbound network access for the 9Router service to prevent unauthorized requests to sensitive internal segments
CVE-2026-103530