{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/megaparse-0.0.55/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:megaparse:megaparse:0.0.55:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85691"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MegaParse (0.0.55)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MegaParse"],"content_html":"\u003cp\u003eMegaParse version 0.0.55 contains a critical server-side request forgery (SSRF) vulnerability in the POST /v1/url endpoint. The application insecurely handles caller-supplied URLs, allowing unauthenticated remote attackers to force the server to perform HTTP requests to arbitrary destinations. By providing internal network addresses or cloud provider metadata service endpoints (e.g., 169.254.169.254) as input, an attacker can bypass access controls and receive the content of those internal requests directly in the application's JSON response. This vulnerability poses a significant risk to organizations deploying MegaParse in cloud-native environments, as it facilitates sensitive data exfiltration, internal reconnaissance, and potential compromise of cloud identity roles.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read responses from internal services that are otherwise unreachable from the internet. In cloud environments, this may result in the exfiltration of IAM credentials or sensitive metadata, leading to privilege escalation or further lateral movement within the cloud infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate MegaParse to a version that addresses CVE-2026-85691 immediately.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the host running MegaParse to prevent connections to internal RFC1918 address space and cloud metadata services.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for POST requests to /v1/url that contain suspicious or internal-only URLs in the request body.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:31:58Z","date_published":"2026-09-04T15:31:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-megaparse-ssrf/","summary":"MegaParse version 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint, allowing attackers to access internal resources and cloud metadata.","title":"Unauthenticated SSRF in MegaParse","url":"https://feed.craftedsignal.io/briefs/2026-09-megaparse-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - MegaParse (0.0.55)","version":"https://jsonfeed.org/version/1.1"}