{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ms-swift/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ms_swift:ms_swift:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85686"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ms-swift (4.5.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf"],"_cs_type":"advisory","_cs_vendors":["ms-swift"],"content_html":"\u003cp\u003eThe ms-swift software, specifically version 4.5.2, contains a critical server-side request forgery (SSRF) vulnerability within its OpenAI-compatible deployment API. The flaw stems from the application's failure to validate or filter media URLs before fetching them from remote sources. Attackers can exploit this by supplying malicious inputs into the 'image_url', 'audio_url', or 'video_url' parameters. When the application processes these parameters, it makes an outbound request to the specified destination. Because these requests lack redirect filtering or destination validation, unauthenticated remote attackers can leverage the affected server to interact with internal resources, probe sensitive network services, or query cloud metadata services (such as the IMDS endpoint at 169.254.169.254) to exfiltrate credentials or configuration metadata. This vulnerability poses a significant risk to organizations running internal services in cloud-hosted environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform unauthorized requests on behalf of the vulnerable server, potentially leading to the discovery of internal infrastructure, unauthorized access to internal services, or the exfiltration of sensitive cloud instance identity and configuration data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of ms-swift 4.5.2 within the environment and restrict their access to internal network resources and cloud metadata endpoints until a patch is applied.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing suspicious 'image_url', 'audio_url', or 'video_url' parameters that point to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or local loopback addresses (127.0.0.1).\u003c/li\u003e\n\u003cli\u003eBlock or monitor outbound traffic from ms-swift deployment servers to common cloud metadata endpoints (169.254.169.254) using firewall or Egress filtering.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:31:31Z","date_published":"2026-09-04T15:31:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ms-swift-ssrf/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability in ms-swift version 4.5.2 allows attackers to perform unauthorized requests to internal network services and cloud metadata endpoints.","title":"Server-Side Request Forgery in ms-swift","url":"https://feed.craftedsignal.io/briefs/2026-09-ms-swift-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Ms-Swift","version":"https://jsonfeed.org/version/1.1"}