{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/hyperdx/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-63731"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HyperDX (before 2.31.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["HyperDX"],"content_html":"\u003cp\u003eA critical Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63731, affects HyperDX versions prior to 2.31.0. This flaw permits authenticated team members to direct the HyperDX server to arbitrary internal destinations. The vulnerability lies within the ClickHouse proxy test endpoint, which lacks proper URL validation and allowlist enforcement for the user-supplied \u003ccode\u003ehost\u003c/code\u003e parameter. Exploiting this vulnerability allows attackers to read reflected error responses, which can contain sensitive internal service response bodies. This enables malicious actors to discover and potentially access internal APIs, container services, and cloud provider metadata endpoints, significantly increasing the risk of data exfiltration and further network compromise. Organizations using HyperDX should prioritize updating to version 2.31.0 or newer to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated team member (attacker) logs into the HyperDX platform, establishing an authorized session.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request specifically targeting the vulnerable ClickHouse proxy test endpoint within the HyperDX application, typically located at a path like \u003ccode\u003e/api/proxy/clickhouse/test\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWithin the request, the attacker injects an arbitrary internal IP address or domain (e.g., \u003ccode\u003e169.254.169.254\u003c/code\u003e for AWS EC2 metadata, \u003ccode\u003e10.0.0.1\u003c/code\u003e for an internal service) into the \u003ccode\u003ehost\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe HyperDX server, without proper validation, attempts to establish a connection to the attacker-specified internal host or service.\u003c/li\u003e\n\u003cli\u003eDuring this connection attempt, the server receives a response (or error) from the internal target, and this response body is reflected back to the attacker as part of the HyperDX application's HTTP response.\u003c/li\u003e\n\u003cli\u003eThe attacker analyzes the reflected data, which may contain sensitive information such as cloud provider credentials, internal API keys, or details about running container services.\u003c/li\u003e\n\u003cli\u003eThis disclosed information facilitates internal network reconnaissance, allowing the attacker to map the internal infrastructure and potentially gain access to further sensitive internal resources.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63731 can lead to significant information disclosure and internal network reconnaissance. Attackers can access sensitive data such as cloud provider metadata (e.g., AWS EC2 instance metadata containing temporary credentials), internal API endpoints, and details about container services running within the organization's infrastructure. While the vulnerability is authenticated, it allows an insider threat or an attacker who has compromised a legitimate user's credentials to escalate privileges and expand their foothold within the network. The CVSS v3.1 Base Score for this vulnerability is 7.7, indicating a high severity risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63731 immediately by updating HyperDX to version 2.31.0 or newer on all affected instances.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-63731 Exploitation - HyperDX SSRF\u0026quot; to your SIEM and tune for your environment to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging for all HyperDX instances to ensure \u003ccode\u003ecs-uri-stem\u003c/code\u003e and \u003ccode\u003ecs-uri-query\u003c/code\u003e fields are captured for the webserver category log source.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T19:23:45Z","date_published":"2026-07-20T19:23:45Z","id":"https://feed.craftedsignal.io/briefs/2026-07-hyperdx-ssrf/","summary":"An authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-63731, in HyperDX before version 2.31.0 by manipulating the `host` parameter of the ClickHouse proxy test endpoint, leading to disclosure of internal service response bodies and potential access to internal APIs, container services, and cloud provider metadata.","title":"Server-Side Request Forgery in HyperDX via ClickHouse Proxy Test Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-07-hyperdx-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - HyperDX","version":"https://jsonfeed.org/version/1.1"}