← Voltar à pesquisa de CVEs

CVE-2026-40242

Arcane

Descrição

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server-s response is returned directly to the caller. type. This constitutes an unauthenticated SSRF vulnerability affecting any publicly reachable Arcane instance. This vulnerability is fixed in 1.17.3.

CVSS 7.2EPSS 0.621%Risco 0.76
Ver fonte
Publicação
2026-04-10 21:16:27
Versões afetadas
<1.17.3
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N