{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/privoce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:privoce:vocechat_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100893"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VoceChat Server (\u003c= 0.5.36)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Privoce"],"content_html":"\u003cp\u003ePrivoce VoceChat Server up to version 0.5.36 contains a server-side request forgery (SSRF) vulnerability. The flaw exists within the open_graph::fetch function located in the src/api/resource.rs file, which powers the open_graphic_parse endpoint. An unauthenticated remote attacker can manipulate the url argument processed by this function to force the server to initiate unauthorized HTTP requests to arbitrary internal or external destinations. This vulnerability has been publicly disclosed, and exploitation is possible. As the vendor has not provided a response or a patch for this issue, defenders must assume the risk of exploitation remains for all instances running version 0.5.36 or earlier.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote attacker to bypass network perimeter defenses by leveraging the server as a proxy. This can lead to unauthorized access to internal services not exposed to the internet, exfiltration of cloud metadata (if hosted in AWS/GCP/Azure environments), or reconnaissance of private network architecture. The vulnerability carries a CVSS v3.1 base score of 7.3, reflecting its potential for significant impact on service integrity and network confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network egress filtering on all servers running VoceChat to prevent unauthorized outbound requests to sensitive internal network ranges or non-essential external endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests to the open_graphic_parse endpoint, specifically looking for unusual URL parameter values or unexpected destination hostnames.\u003c/li\u003e\n\u003cli\u003eDue to the lack of a vendor-provided patch, consider placing the VoceChat instance behind a Web Application Firewall (WAF) and configure rules to inspect and restrict the 'url' parameter passed to the open_graphic_parse endpoint.\u003c/li\u003e\n\u003cli\u003eIf the application functionality is not critical, disable the open_graphic_parse endpoint entirely.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T05:11:57Z","date_published":"2026-09-28T05:11:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vocechat-ssrf/","summary":"Privoce VoceChat Server versions up to 0.5.36 are vulnerable to server-side request forgery via the open_graphic_parse endpoint, allowing remote attackers to perform unauthorized outbound requests.","title":"Server-Side Request Forgery in Privoce VoceChat Server","url":"https://feed.craftedsignal.io/briefs/2026-09-vocechat-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Privoce","version":"https://jsonfeed.org/version/1.1"}