


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the f…
Published:
2 August 2026 at 22:00:00
Alert date:
3 August 2026 at 22:01:37
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
A server-side request forgery (SSRF) vulnerability has been identified in jina-ai reader up to commit 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. The vulnerability exists in the isValidTLD function within the Crawler/Puppeteer component, specifically in the file /backend/functions/src/cloud-functions/crawler.ts. Remote attackers can exploit this flaw to perform SSRF attacks. A public exploit has been disclosed and may be actively used. The product uses a rolling release model, so no specific version numbers are provided for affected or patched releases. The vendor was notified prior to public disclosure but did not respond. This vulnerability poses a significant risk as SSRF can be used to pivot attacks into internal networks or cloud metadata services.
Technical details
Mitigation steps:
Affected products:
jina-ai reader
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18647
https://github.com/orionyan520/cve_report/issues/8
https://vuldb.com/cve/CVE-2026-18647
https://vuldb.com/submit/855011
https://vuldb.com/vuln/385566
https://vuldb.com/vuln/385566/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
