{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tarzan-cms-1.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:taisan:tarzan_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90710"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["tarzan-cms (1.0.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-vulnerability"],"_cs_type":"threat","_cs_vendors":["taisan"],"content_html":"\u003cp\u003eA Server-Side Request Forgery (SSRF) vulnerability has been identified in tarzan-cms version 1.0.0. The flaw resides within the openConnection function of the ThemeService.java file, specifically within the Theme Download component. An unauthenticated remote attacker can exploit this by manipulating the httpUrl argument, causing the server to perform arbitrary outbound HTTP requests. This vulnerability, tracked as CVE-2026-90710, allows attackers to interact with internal network resources, potentially leading to unauthorized data access or service disruption within the hosting infrastructure. The vulnerability has been publicly disclosed, and as of the report date, the maintainers have not issued a patch or response. Defenders should treat this as a high-risk entry point for reconnaissance and potential lateral movement.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote attacker to force the tarzan-cms application server to make requests to unintended destinations. This can be leveraged to scan internal networks, access sensitive internal APIs or metadata services (like AWS/Azure IMDS), and potentially bypass firewall restrictions. There is currently no vendor patch available, leaving all deployments of version 1.0.0 exposed to active exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for requests to the Theme Download endpoint containing suspicious or internal network IP addresses (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, or localhost) in the httpUrl parameter.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the application server to prevent it from initiating outbound requests to internal resources.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the application server to permit only necessary outbound traffic to trusted domains or IP ranges.\u003c/li\u003e\n\u003cli\u003eDisable the Theme Download functionality if it is not business-critical until a vendor patch is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T13:33:41Z","date_published":"2026-09-14T13:33:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tarzan-cms-ssrf/","summary":"An unauthenticated remote SSRF vulnerability exists in the Theme Download Function of tarzan-cms 1.0.0 due to insecure handling of the httpUrl parameter.","title":"SSRF Vulnerability in tarzan-cms Theme Download Function","url":"https://feed.craftedsignal.io/briefs/2026-09-tarzan-cms-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Tarzan-Cms (1.0.0)","version":"https://jsonfeed.org/version/1.1"}