CVE-2026-92215
Received Received - Intake

Server-Side Request Forgery in a2ui

Vulnerability report for CVE-2026-92215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulDB

Description

A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The identifier of the patch is 2bb8423060308bbdea8ba468dabed4fc256d18ea. To fix this issue, it is recommended to deploy a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
a2ui-project a2ui to 0.10.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the a2ui project's FileResolver component. The issue occurs because the resolver performs HTTP(S) fetches without properly restricting allowed hosts by default. This allows attackers to make arbitrary requests from the server, including accessing private IP ranges or cloud metadata endpoints. The vulnerability is exacerbated by redirect handling without host validation, enabling DNS rebinding attacks.

Detection Guidance

To detect this SSRF vulnerability in a2ui, check if the FileResolver component is configured with an empty or unrestricted allowed_hosts list. Inspect the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py for default settings. Look for evidence of HTTP(S) requests to private IP ranges, cloud metadata endpoints, or unexpected external hosts. Monitor network traffic for outbound requests to restricted or internal addresses.

Impact Analysis

An attacker could exploit this to force the server to make unauthorized requests to internal systems or external services. This may lead to data exfiltration, internal network reconnaissance, or unauthorized access to sensitive endpoints like cloud metadata services. Systems using the vulnerable a2ui versions could be used as stepping stones for further attacks.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data access or exfiltration. GDPR may be breached if personal data is exposed through SSRF attacks. HIPAA could be violated if protected health information is accessed or transmitted improperly. Organizations must ensure proper network segmentation and access controls to mitigate such risks.

Mitigation Strategies

Apply the patch from commit 2bb8423060308bbdea8ba468dabed4fc256d18ea. Set allowed_hosts to an empty list to deny all remote hosts by default. Configure explicit allowlists for permitted domains. Validate IP addresses during URL resolution to block private, loopback, link-local, and multicast addresses. Implement strict redirect handling with scheme validation and limit redirect chains.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart