<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>JeecgBoot - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jeecgboot/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 07:22:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jeecgboot/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-19000 Server-Side Request Forgery in JeecgBoot</title><link>https://feed.craftedsignal.io/briefs/2026-08-jeecgboot-ssrf/</link><pubDate>Thu, 06 Aug 2026 07:22:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-jeecgboot-ssrf/</guid><description>An unauthenticated server-side request forgery (SSRF) vulnerability in the JeecgBoot 'Anonymous Chat Attachment Parser' allows remote attackers to perform unauthorized requests via the /airag/chat/send endpoint.</description><content:encoded><![CDATA[<p>A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-19000, has been disclosed in JeecgBoot versions up to 3.9.2. The vulnerability resides within the Anonymous Chat Attachment Parser component, specifically in an undocumented function associated with the /airag/chat/send endpoint. Remote, unauthenticated attackers can exploit this flaw to induce the application server to perform unauthorized HTTP requests to internal or external resources. Given the availability of public exploit material, there is a risk of active exploitation for reconnaissance or interaction with internal services that are not directly exposed to the internet. Defenders should prioritize patching or restricting access to the affected endpoint until a vendor-supplied update is available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this SSRF vulnerability may allow attackers to bypass network perimeter controls to scan internal networks, retrieve sensitive metadata from cloud environments (e.g., IMDS), or interact with internal APIs that rely on implicit trust. This represents a significant risk for organizations hosting JeecgBoot in environments with sensitive internal network segments or cloud-native infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rule to detect attempts to reach the vulnerable endpoint.</li>
<li>Implement strict firewall or web application firewall (WAF) rules to restrict access to the /airag/chat/send endpoint if it is not required for business operations.</li>
<li>Monitor server access logs for anomalous outbound HTTP requests originating from the JeecgBoot server process.</li>
<li>Upgrade JeecgBoot to the latest version once a fix is released.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ssrf</category><category>web-vulnerability</category></item></channel></rss>