top of page
perceptive_background_267k.jpg

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connectio…

Published:

1 september 2026 om 00:00:00

Alert date:

1 september 2026 om 22:02:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Network Infrastructure

Wyoming before version 1.10.2 contains a server-side request forgery (SSRF) vulnerability identified as CVE-2026-8712. Unauthenticated attackers with network access can exploit this flaw by supplying a malicious `uri` query parameter to the HTTP API. The vulnerability allows attackers to force outbound connections to arbitrary targets using `tcp://` or `unix://` URI schemes. Affected endpoints include /api/info, /api/speech-to-text, and /api/text-to-speech. Exploitation enables attackers to override the server-configured backend and redirect connections to attacker-chosen hosts. No authentication is required, making this accessible to any network-adjacent attacker. The issue has been patched in Wyoming version 1.10.2. Users are advised to upgrade immediately to mitigate the risk of internal network probing or service abuse.

Technical details

Mitigation steps:

Affected products:

Wyoming

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page