CVE-2026-103530
Deferred Deferred - Pending Action

Server-Side Request Forgery in decolua 9Router

Vulnerability report for CVE-2026-103530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
decolua 9router to 0.5.55 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Server-Side Request Forgery (SSRF) flaw in decolua 9Router up to version 0.5.55. It exists in the fetch function of src/shared/utils/ssrfGuard.js within the Search Endpoint component. The issue allows attackers to manipulate the provider_options.baseUrl parameter to force the server to make requests to unintended internal or external hosts. The SSRF guard designed to prevent this has multiple bypasses, including weak hostname checks, improper IP validation, and failure to re-validate redirect targets.

Detection Guidance

To detect this SSRF vulnerability in decolua 9Router up to 0.5.55, inspect the /v1/search endpoint for requests where the provider_options.baseUrl parameter is set to loopback addresses, IPv6-mapped IPv4 addresses, or hostnames with trailing dots (e.g., localhost.). Check if the server makes direct fetch requests to these user-supplied URLs without proper IP resolution or redirect validation. Review logs for requests tagged with x-9r-real-ip: 127.0.0.1 and internal tokens.

Impact Analysis

An attacker could exploit this to access internal hosts, cloud metadata endpoints, or local services by bypassing SSRF protections. This could lead to exfiltration of sensitive API keys, probing of internal networks, or bypassing authentication on local endpoints. The vulnerability allows remote initiation of attacks without requiring user interaction.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Exposure of API keys or internal service access may result in data breaches, triggering compliance violations and potential regulatory penalties due to inadequate security controls.

Mitigation Strategies

Immediately update to the patched version of 9Router (post-0.5.55) that includes fixes for SSRF guard bypasses. Disable the provider_options.baseUrl override feature or restrict it to administrators only. Implement DNS resolution checks in the SSRF guard to block loopback and private IP resolutions. Disable automatic redirect following or re-validate redirect targets. Remove automatic trust of loopback requests for authentication middleware.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart