{"id":"CVE-2026-63731","summary":"HyperDX \u003c 2.31.0 SSRF via ClickHouse Proxy Test Endpoint","details":"HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test endpoint with no URL validation or allowlist enforcement. Attackers can exploit the reflected error responses from the endpoint to disclose internal service response bodies, enabling access to internal APIs, container services, and cloud provider metadata endpoints.","modified":"2026-07-22T05:32:31.712149628Z","published":"2026-07-20T18:45:14.088Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63731.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63731.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63731"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hyperdx-ssrf-via-clickhouse-proxy-test-endpoint"},{"type":"REPORT","url":"https://github.com/hyperdxio/hyperdx/issues/2588"},{"type":"FIX","url":"https://github.com/hyperdxio/hyperdx/commit/1705b37ac68acc222cd038327ed79e167e256a1b"},{"type":"FIX","url":"https://github.com/hyperdxio/hyperdx/pull/2593"},{"type":"FIX","url":"https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0"},{"type":"PACKAGE","url":"https://github.com/hyperdxio/hyperdx"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hyperdxio/hyperdx","events":[{"introduced":"c26ee9164aabbb6aad487f8cf4ee3efb1546a535"},{"fixed":"4b1aefbae22ac02bffbdf7fca932f43095d3d8d6"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.31.0"}],"source":"AFFECTED_FIELD"}}],"versions":["@hyperdx/otel-collector@2.30.1","@hyperdx/hdx-eval@0.2.1","@hyperdx/common-utils@0.22.0","@hyperdx/cli@0.5.2","@hyperdx/app@2.30.1","@hyperdx/api@2.30.1","cli-v0.5.2","@hyperdx/otel-collector@2.30.0","@hyperdx/app@2.30.0","@hyperdx/api@2.30.0","cli-v0.5.1","@hyperdx/otel-collector@2.29.0","@hyperdx/hdx-eval@0.2.0","@hyperdx/common-utils@0.21.0","@hyperdx/cli@0.5.1","@hyperdx/app@2.29.0","@hyperdx/api@2.29.0","cli-v0.5.0","@hyperdx/otel-collector@2.28.0","@hyperdx/common-utils@0.20.0","@hyperdx/cli@0.5.0","@hyperdx/app@2.28.0","@hyperdx/api@2.28.0","@hyperdx/otel-collector@2.27.0","@hyperdx/common-utils@0.19.1","@hyperdx/cli@0.4.1","@hyperdx/app@2.27.0","@hyperdx/api@2.27.0","cli-v0.4.1","@hyperdx/otel-collector@2.24.1","@hyperdx/common-utils@0.18.1","@hyperdx/cli@0.4.0","@hyperdx/app@2.24.1","@hyperdx/api@2.24.1","cli-v0.4.0","cli-v0.3.0","cli-v0.2.1","@hyperdx/otel-collector@2.23.1","@hyperdx/common-utils@0.17.1","@hyperdx/cli@0.2.0","@hyperdx/app@2.23.1","@hyperdx/api@2.23.1","@hyperdx/otel-collector@2.23.0","@hyperdx/common-utils@0.17.0","@hyperdx/app@2.23.0","@hyperdx/api@2.23.0","@hyperdx/otel-collector@2.22.1","@hyperdx/common-utils@0.16.2","@hyperdx/app@2.22.1","@hyperdx/api@2.22.1","@hyperdx/otel-collector@2.22.0","@hyperdx/common-utils@0.16.1","@hyperdx/app@2.22.0","@hyperdx/api@2.22.0","@hyperdx/otel-collector@2.21.0","@hyperdx/common-utils@0.16.0","@hyperdx/app@2.21.0","@hyperdx/api@2.21.0","@hyperdx/otel-collector@2.20.0","@hyperdx/common-utils@0.15.0","@hyperdx/app@2.20.0","@hyperdx/api@2.20.0","@hyperdx/otel-collector@2.19.0","@hyperdx/common-utils@0.14.0","@hyperdx/app@2.19.0","@hyperdx/api@2.19.0","@hyperdx/otel-collector@2.18.0","@hyperdx/common-utils@0.13.0","@hyperdx/app@2.18.0","@hyperdx/api@2.18.0","@hyperdx/otel-collector@2.17.0","@hyperdx/common-utils@0.12.3","@hyperdx/app@2.17.0","@hyperdx/api@2.17.0","@hyperdx/otel-collector@2.16.0","@hyperdx/common-utils@0.12.2","@hyperdx/app@2.16.0","@hyperdx/api@2.16.0","@hyperdx/otel-collector@2.15.1","@hyperdx/common-utils@0.12.1","@hyperdx/app@2.15.1","@hyperdx/api@2.15.1","@hyperdx/otel-collector@2.15.0","@hyperdx/common-utils@0.12.0","@hyperdx/app@2.15.0","@hyperdx/api@2.15.0","@hyperdx/otel-collector@2.14.0","@hyperdx/common-utils@0.11.1","@hyperdx/app@2.14.0","@hyperdx/api@2.14.0","@hyperdx/common-utils@0.10.1","@hyperdx/app@2.11.0","@hyperdx/api@2.11.0","@hyperdx/common-utils@0.11.0","@hyperdx/app@2.13.0","@hyperdx/api@2.13.0","@hyperdx/common-utils@0.10.2","@hyperdx/app@2.12.0","@hyperdx/api@2.12.0","@hyperdx/common-utils@0.10.0","@hyperdx/app@2.10.0","@hyperdx/api@2.10.0","@hyperdx/common-utils@0.9.0","@hyperdx/app@2.9.0","@hyperdx/api@2.9.0","@hyperdx/common-utils@0.8.0","@hyperdx/app@2.8.0","@hyperdx/api@2.8.0","@hyperdx/common-utils@0.7.2","@hyperdx/app@2.7.1","@hyperdx/api@2.7.1","@hyperdx/common-utils@0.7.1","@hyperdx/app@2.7.0","@hyperdx/api@2.7.0","@hyperdx/common-utils@0.7.0","@hyperdx/app@2.6.0","@hyperdx/api@2.6.0","@hyperdx/common-utils@0.6.0","@hyperdx/app@2.5.0","@hyperdx/api@2.5.0","@hyperdx/common-utils@0.5.0","@hyperdx/app@2.4.0","@hyperdx/api@2.4.0","@hyperdx/common-utils@0.4.0","@hyperdx/app@2.3.0","@hyperdx/api@2.3.0","@hyperdx/common-utils@0.3.2","@hyperdx/app@2.2.2","@hyperdx/api@2.2.2","@hyperdx/common-utils@0.3.1","@hyperdx/app@2.2.1","@hyperdx/api@2.2.1","@hyperdx/common-utils@0.3.0","@hyperdx/app@2.2.0","@hyperdx/api@2.2.0","@hyperdx/common-utils@0.2.9","@hyperdx/app@2.1.2","@hyperdx/api@2.1.2","@hyperdx/common-utils@0.2.8","@hyperdx/app@2.1.1","@hyperdx/api@2.1.1","@hyperdx/common-utils@0.2.7","@hyperdx/app@2.1.0","@hyperdx/api@2.1.0","@hyperdx/common-utils@0.2.6","@hyperdx/app@2.0.6","@hyperdx/api@2.0.6","@hyperdx/common-utils@0.2.5","@hyperdx/app@2.0.5","@hyperdx/api@2.0.5","@hyperdx/common-utils@0.2.4","@hyperdx/app@2.0.4","@hyperdx/api@2.0.4","@hyperdx/common-utils@0.2.3","@hyperdx/app@2.0.3","@hyperdx/api@2.0.3","@hyperdx/common-utils@0.2.2","@hyperdx/app@2.0.2","@hyperdx/api@2.0.2","@hyperdx/common-utils@0.2.1","@hyperdx/app@2.0.1","@hyperdx/api@2.0.1","@hyperdx/common-utils@0.2.0","@hyperdx/app@2.0.0","@hyperdx/api@2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63731.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"}]}