{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/kyegomez/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-67346"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Swarms"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["kyegomez"],"content_html":"\u003cp\u003eThe Swarms library, in versions through 6.8.1, contains a server-side request forgery (SSRF) vulnerability due to improper hostname validation within the _is_safe_url function. The function fails to validate hostnames after DNS resolution, enabling an attacker to bypass intended blocklists. By submitting user-controlled URLs - specifically for image or audio processing - an attacker can trick the application into performing requests to private IP addresses, loopback addresses, or sensitive cloud metadata services. This vulnerability, identified as CVE-2026-67346, poses a high risk as it allows for unauthorized access to internal services, potentially leading to the exfiltration of credentials or sensitive environment data. The issue was addressed in commit 8b0fc9e.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to interact with internal network resources that are otherwise unreachable from the public internet. This can result in unauthorized access to sensitive internal services, exfiltration of cloud metadata (such as IAM role credentials in AWS or GCP environments), and potential compromise of the host environment depending on the sensitivity of reachable internal endpoints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Swarms library to a version containing the fix from commit 8b0fc9e immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on servers running the library to prevent unauthorized requests to internal infrastructure or private metadata services (e.g., 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eUse network segmentation to isolate applications that handle user-supplied URLs from critical internal services.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unexpected outbound requests originating from the application server context.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T15:33:35Z","date_published":"2026-07-30T15:33:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-swarms-ssrf/","summary":"The Swarms library contains a server-side request forgery (SSRF) vulnerability in the _is_safe_url function that allows attackers to bypass blocklists and access restricted internal services.","title":"SSRF Vulnerability in Swarms library","url":"https://feed.craftedsignal.io/briefs/2026-07-swarms-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Kyegomez","version":"https://jsonfeed.org/version/1.1"}