GHSA-mgq6-mc59-8j8mMediumCVSS 5.8
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers...
🔗 CVE IDs covered (1)
📋 Description
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
🔗 References (5)
- https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch
- https://nvd.nist.gov/vuln/detail/CVE-2026-82477
- https://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b485937b
- https://github.com/mitre/heimdall2/releases/tag/v2.14.0
- https://github.com/advisories/GHSA-mgq6-mc59-8j8m