{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wyoming/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wyoming:wyoming:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-8712"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wyoming (\u003c 1.10.2)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Wyoming"],"content_html":"\u003cp\u003eWyoming versions prior to 1.10.2 are susceptible to a server-side request forgery (SSRF) vulnerability (CVE-2026-8712). The flaw resides in the handling of the 'uri' query parameter within the application's HTTP API. An unauthenticated attacker with network access to the API can craft malicious requests to endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech. By supplying an arbitrary URI using 'tcp://' or 'unix://' protocols, an attacker can override the server-configured backend settings, forcing the application to initiate unauthorized outbound connections. This capability allows attackers to bypass network perimeters, perform reconnaissance on internal services, or interact with sensitive endpoints that are otherwise unreachable from the public internet. Given the potential for lateral movement and access to internal data, this vulnerability represents a significant risk for deployments exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform server-side request forgery, potentially leading to unauthorized interaction with internal services or restricted network infrastructure. If exploited, an attacker could gain insights into internal network topology, extract information from local services, or potentially trigger further downstream vulnerabilities, depending on the environment where Wyoming is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Wyoming to version 1.10.2 or later to remediate the SSRF vulnerability in the API.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to restrict access to the Wyoming HTTP API endpoints to trusted IP addresses only.\u003c/li\u003e\n\u003cli\u003eDeploy egress filtering on the host machine running Wyoming to limit outbound connections to only authorized internal backend services or external destinations.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for unusual 'uri' parameters containing 'tcp://' or 'unix://' prefixes directed at /api/info, /api/speech-to-text, or /api/text-to-speech.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T21:08:10Z","date_published":"2026-09-01T21:08:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wyoming-ssrf/","summary":"Wyoming versions prior to 1.10.2 contain a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to redirect outbound API connections to arbitrary network targets.","title":"SSRF Vulnerability in Wyoming API","url":"https://feed.craftedsignal.io/briefs/2026-09-wyoming-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Wyoming","version":"https://jsonfeed.org/version/1.1"}