CVE-2026-91199
Deferred Deferred - Pending Action

Server-Side Request Forgery in Refly

Vulnerability report for CVE-2026-91199, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-23

Assigner: VulnCheck

Description

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses including cloud metadata services to read page titles and descriptions of internal resources.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-23
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
refly refly 1.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side request forgery (SSRF) in Refly version 1.1.0. It exists in the POST /v1/misc/scrape endpoint, which fetches URLs provided by users without proper validation of the scheme, host, or resolved address. Authenticated attackers can exploit this to make the backend send requests to loopback, private, and link-local addresses, including cloud metadata services. This allows reading page titles and descriptions of internal resources.

Detection Guidance

To detect this SSRF vulnerability in Refly 1.1.0, monitor network traffic for outbound requests from the server to loopback, private, or link-local addresses. Check logs for POST requests to /v1/misc/scrape with unusual URLs. Use tools like tcpdump or Wireshark to inspect traffic for internal IP ranges (e.g., 127.0.0.1, 10.0.0.0/8, 192.168.0.0/16).

Inspect application logs for backend requests to cloud metadata services (e.g., AWS, Azure, GCP endpoints). Test by sending crafted requests to the /v1/misc/scrape endpoint with internal URLs and observe if responses are returned.

Impact Analysis

Authenticated attackers could exploit this to access internal resources, potentially exposing sensitive data like page titles and descriptions from internal systems. This could lead to information disclosure, unauthorized access to internal services, or further attacks on internal infrastructure if combined with other vulnerabilities.

Compliance Impact

This vulnerability could lead to unauthorized access to internal resources, potentially violating data protection requirements under GDPR and HIPAA. It may result in unauthorized disclosure of personal or sensitive data, leading to compliance breaches, regulatory penalties, and loss of trust.

Mitigation Strategies

Upgrade Refly to a patched version if available. If not, restrict access to the /v1/misc/scrape endpoint to trusted users only. Implement strict URL validation to block requests to loopback, private, or link-local addresses. Use allowlists for permitted domains.

Configure firewalls or network policies to prevent outbound connections to internal IP ranges from the application server. Monitor and log all requests to the vulnerable endpoint for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91199. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart