<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>9Router (&lt; 0.5.56) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/9router--0.5.56/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 00:37:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/9router--0.5.56/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in decolua 9Router</title><link>https://feed.craftedsignal.io/briefs/2026-10-ssrf-decolua-9router/</link><pubDate>Thu, 01 Oct 2026 00:37:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ssrf-decolua-9router/</guid><description>A server-side request forgery vulnerability in decolua 9Router versions up to 0.5.55 allows remote attackers to manipulate the provider_options.baseUrl argument to trigger unauthorized requests.</description><content:encoded><![CDATA[<p>CVE-2026-103530 identifies a server-side request forgery (SSRF) vulnerability affecting decolua 9Router in all versions up to and including 0.5.55. The vulnerability resides within the fetch function of the file src/shared/utils/ssrfGuard.js, which is part of the application's Search Endpoint component.</p>
<p>An attacker can exploit this flaw by remotely sending a crafted request that manipulates the provider_options.baseUrl argument. This manipulation forces the application to perform unauthorized requests to arbitrary internal or external resources, potentially leading to unauthorized data access, internal service discovery, or interaction with internal APIs that expect requests only from the trusted server environment. Impact is significant given the ability to bypass network segmentation by leveraging the server's context.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to perform SSRF attacks, potentially leading to unauthorized interaction with internal infrastructure, sensitive service exposure, or exfiltration of metadata from cloud instances or internal systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Upgrade 9Router to version 0.5.56 or later to apply the necessary security patch for the ssrfGuard.js component. Implement network egress filtering on the host running the 9Router service to restrict unauthorized outbound connections to internal segments.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>vulnerability</category><category>web-application</category></item></channel></rss>