OpenViking before 0.3.4 contains a server-side request...
High severity
Unreviewed
Published
Aug 21, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Description
Published by the National Vulnerability Database
Aug 21, 2026
Published to the GitHub Advisory Database
Aug 21, 2026
Last updated
Aug 21, 2026
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.
References