Advisories for Pypi/Opencve package

2026

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

OpenCVE contains a Server-Side Request Forgery (SSRF) vulnerability in the notification testing functionality for both Webhook and Slack integrations. An authenticated user with permission to configure notification channels can trigger test requests to arbitrary HTTP(S) endpoints. Insufficient validation of target destinations allows requests to be sent to hosts reachable from the OpenCVE server, including internal network resources, localhost interfaces, and cloud metadata services. Successful exploitation could allow an attacker to …