<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Privoce - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/privoce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 05:11:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/privoce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Server-Side Request Forgery in Privoce VoceChat Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-vocechat-ssrf/</link><pubDate>Mon, 28 Sep 2026 05:11:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-vocechat-ssrf/</guid><description>Privoce VoceChat Server versions up to 0.5.36 are vulnerable to server-side request forgery via the open_graphic_parse endpoint, allowing remote attackers to perform unauthorized outbound requests.</description><content:encoded><![CDATA[<p>Privoce VoceChat Server up to version 0.5.36 contains a server-side request forgery (SSRF) vulnerability. The flaw exists within the open_graph::fetch function located in the src/api/resource.rs file, which powers the open_graphic_parse endpoint. An unauthenticated remote attacker can manipulate the url argument processed by this function to force the server to initiate unauthorized HTTP requests to arbitrary internal or external destinations. This vulnerability has been publicly disclosed, and exploitation is possible. As the vendor has not provided a response or a patch for this issue, defenders must assume the risk of exploitation remains for all instances running version 0.5.36 or earlier.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote attacker to bypass network perimeter defenses by leveraging the server as a proxy. This can lead to unauthorized access to internal services not exposed to the internet, exfiltration of cloud metadata (if hosted in AWS/GCP/Azure environments), or reconnaissance of private network architecture. The vulnerability carries a CVSS v3.1 base score of 7.3, reflecting its potential for significant impact on service integrity and network confidentiality.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement network egress filtering on all servers running VoceChat to prevent unauthorized outbound requests to sensitive internal network ranges or non-essential external endpoints.</li>
<li>Monitor web server access logs for anomalous requests to the open_graphic_parse endpoint, specifically looking for unusual URL parameter values or unexpected destination hostnames.</li>
<li>Due to the lack of a vendor-provided patch, consider placing the VoceChat instance behind a Web Application Firewall (WAF) and configure rules to inspect and restrict the 'url' parameter passed to the open_graphic_parse endpoint.</li>
<li>If the application functionality is not critical, disable the open_graphic_parse endpoint entirely.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>web-application</category><category>vulnerability</category></item></channel></rss>