{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/decolua/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-103530"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["9Router (\u003c 0.5.56)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["decolua"],"content_html":"\u003cp\u003eCVE-2026-103530 identifies a server-side request forgery (SSRF) vulnerability affecting decolua 9Router in all versions up to and including 0.5.55. The vulnerability resides within the fetch function of the file src/shared/utils/ssrfGuard.js, which is part of the application's Search Endpoint component.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this flaw by remotely sending a crafted request that manipulates the provider_options.baseUrl argument. This manipulation forces the application to perform unauthorized requests to arbitrary internal or external resources, potentially leading to unauthorized data access, internal service discovery, or interaction with internal APIs that expect requests only from the trusted server environment. Impact is significant given the ability to bypass network segmentation by leveraging the server's context.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to perform SSRF attacks, potentially leading to unauthorized interaction with internal infrastructure, sensitive service exposure, or exfiltration of metadata from cloud instances or internal systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade 9Router to version 0.5.56 or later to apply the necessary security patch for the ssrfGuard.js component. Implement network egress filtering on the host running the 9Router service to restrict unauthorized outbound connections to internal segments.\u003c/p\u003e\n","date_modified":"2026-10-01T00:37:29Z","date_published":"2026-10-01T00:37:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ssrf-decolua-9router/","summary":"A server-side request forgery vulnerability in decolua 9Router versions up to 0.5.55 allows remote attackers to manipulate the provider_options.baseUrl argument to trigger unauthorized requests.","title":"SSRF Vulnerability in decolua 9Router","url":"https://feed.craftedsignal.io/briefs/2026-10-ssrf-decolua-9router/"}],"language":"en","title":"CraftedSignal Threat Feed - Decolua","version":"https://jsonfeed.org/version/1.1"}