{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/keep-commit-91c75e0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-65057"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Keep (commit 91c75e0)"],"_cs_severities":["critical"],"_cs_tags":["SSRF","vulnerability","cloud","web-vulnerability","credential-theft"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-65057 describes a critical server-side request forgery (SSRF) vulnerability affecting Keep (specifically commit 91c75e0). Unauthenticated attackers can exploit this flaw by sending a specially crafted JSON payload to an unprotected healthcheck endpoint. The payload contains a malicious \u003ccode\u003ehost\u003c/code\u003e parameter, which the vulnerable Keep backend then uses to initiate arbitrary HTTP requests. This allows attackers to compel the server to communicate with internal network services or critical cloud metadata endpoints. Successful exploitation facilitates internal network reconnaissance, mapping an organization's network infrastructure, and more critically, the theft of sensitive cloud credentials, potentially leading to widespread compromise of cloud resources. This vulnerability was published on July 21, 2026, and its CVSS v3.1 base score of 9.3 highlights its severe potential impact.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a vulnerable instance of Keep (commit 91c75e0) exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JSON payload containing a \u003ccode\u003ehost\u003c/code\u003e parameter with a value pointing to an internal service IP address (e.g., \u003ccode\u003e10.0.0.1\u003c/code\u003e) or a cloud metadata service endpoint (e.g., \u003ccode\u003e169.254.169.254/latest/meta-data\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker sends this crafted JSON payload as an HTTP request to the unprotected \u003ccode\u003e/healthcheck\u003c/code\u003e endpoint of the vulnerable Keep application.\u003c/li\u003e\n\u003cli\u003eThe Keep backend processes the request, and due to the SSRF vulnerability, it initiates an arbitrary outbound HTTP request using the attacker-controlled \u003ccode\u003ehost\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe backend application attempts to connect to the specified internal service or cloud metadata endpoint, fetching its response.\u003c/li\u003e\n\u003cli\u003eThe response from the internal service or metadata endpoint is returned to the attacker through the vulnerable Keep application, enabling internal network reconnaissance by mapping reachable services.\u003c/li\u003e\n\u003cli\u003eIf targeting cloud metadata services, the attacker extracts temporary cloud credentials, API keys, or other sensitive configuration data from the responses.\u003c/li\u003e\n\u003cli\u003eThe attacker can then use the stolen cloud credentials to gain unauthorized access to cloud resources and further compromise the environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65057 can lead to severe consequences for organizations utilizing the affected Keep software. Attackers can perform extensive internal network reconnaissance, mapping out private network segments and identifying other vulnerable systems or services that are typically not exposed externally. The most critical impact is the potential theft of cloud credentials from metadata services, granting attackers unauthorized access to an organization's cloud environment. This could result in data exfiltration, service disruption, or further lateral movement within cloud infrastructure, leading to significant financial and reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-65057 immediately\u003c/strong\u003e by updating Keep to a patched version beyond commit 91c75e0, if available, or applying vendor-provided mitigation steps.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-65057 Exploitation - Keep SSRF Attempt\u0026quot; to your SIEM to detect attempts to exploit the \u003ccode\u003e/healthcheck\u003c/code\u003e endpoint using internal IP addresses or cloud metadata service hostnames.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging for the \u003ccode\u003ewebserver\u003c/code\u003e category to ensure \u003ccode\u003ecs-uri-stem\u003c/code\u003e and \u003ccode\u003ecs-uri-query\u003c/code\u003e fields are captured, which are crucial for the detection rule.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and egress filtering to prevent internal systems from making arbitrary outbound connections, especially to private IP ranges or metadata service IPs, even if a server-side application is compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T21:22:00Z","date_published":"2026-07-21T21:22:00Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-65057-keep-ssrf/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.","title":"CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-65057-keep-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Keep (Commit 91c75e0)","version":"https://jsonfeed.org/version/1.1"}