CVE-2025-58441
Unknown
Unknown - Not Provided
Blind SSRF Vulnerability in Knowage BI Suite Allows Internal Scanning
Publication date: 2026-01-07
Last updated on: 2026-02-03
Assigner: GitHub, Inc.
Description
Description
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| knowagelabs | knowage-server | to 8.1.37 (exc) |
| eng | knowage | to 8.1.37 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-918 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. |