{"id":"CVE-2026-18359","summary":"Server-Side Request Forgery (SSRF) in eScriptorium","details":"Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied","modified":"2026-09-25T03:46:28.976459744Z","published":"2026-08-06T15:11:13.252Z","database_specific":{"cna_assigner":"GitLab","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18359.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"26.4.1"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"26.04.1"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://gitlab.com/scripta/escriptorium/-/work_items/1230"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18359.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18359"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/scripta/escriptorium","events":[{"introduced":"0"},{"last_affected":"d97631d5c0279df78a26bd0611c2cf268c73202e"}],"database_specific":{"cpe":"cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"26.04.1"}],"source":"CPE_RANGE"}}],"versions":["v1.0.0","26.04b1","base-kraken7","dev-pre-release","base-dj-solo","dev-new-ui-alpha-rev8","dev-0.14.2","dev-new-ui-alpha-rev7","dev-new-ui-alpha-rev6","dev-new-ui-alpha-rev5","dev-beta-0.14.1","dev-new-ui-alpha-rev4","dev-new-ui-alpha-rev3","dev-beta-0.14","base-django42","dev-new-ui-alpha-rev2","dev-new-ui-alpha-rev1","dev-new-ui-alpha","dev-staging","base-0.13.8-django-4.1","dev-revert-pyes","base-0.13.7-revert-pyes","base-kraken4312","base-kraken439b","base-kraken439","base-kraken435","dev0.13.3d","dev0.13.3c","dev0.13.3b","dev0.13.3","dev0.13.1c","base-kraken42","v0.12.2b","v0.12.2","base-0.12.2b","base-0.12.2","v0.12.1-dev","base-0.10.5","base-0.10.1b","v0.5.1c","v0.5.1b","v0.5.1","v0.5","v0.4.1","v0.4","v0.3","v0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18359.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}