Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set to False, disabling TLS verification.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 31 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unvalidated SSRF Allowing Internal Resource Access via /har/test Endpoint | |
| Weaknesses | CWE-918 |
Mon, 31 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set to False, disabling TLS verification. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-31T15:21:14.112Z
Reserved: 2026-06-07T00:00:00.000Z
Link: CVE-2026-51152
No data.
Status : Received
Published: 2026-08-31T16:18:34.220
Modified: 2026-08-31T16:18:34.220
Link: CVE-2026-51152
No data.
OpenCVE Enrichment
Updated: 2026-08-31T16:30:05Z
Weaknesses