Description
Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set to False, disabling TLS verification.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unvalidated SSRF Allowing Internal Resource Access via /har/test Endpoint

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Qd
Qd qd
Vendors & Products Qd
Qd qd

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unvalidated SSRF Allowing Internal Resource Access via /har/test Endpoint
Weaknesses CWE-918

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set to False, disabling TLS verification.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T13:56:39.553Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51152

cve-icon Vulnrichment

Updated: 2026-09-01T13:56:35.471Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:34.220

Modified: 2026-09-01T14:17:29.120

Link: CVE-2026-51152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T17:45:07Z

Weaknesses