← back
CVE-2026-65618mediumCWE-918

Improper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.2%
from disclosure to weapon
Published on NVDJul 27
victimsJul 20
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
Appeared in 1 incident(s) we investigated
Hugging Face
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
jfrog · artifactory