Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-72552

CVE-2026-72552: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-72552] Server-Side Request Forgery allows information disclosure and internal network scanning

    CVE-2026-72552Source published Source updated

    A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints. A flaw was found in Dub. This can be exploited via the `metatags` edge endpoint, which processes caller-supplied URLs without proper validation or authentication. Successful exploitation could lead to information disclosure, such as scanning internal services or exfiltrating data from cloud metadata endpoints. An unauthenticated remote attacker can supply arbitrary…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Restrict outbound network connectivity from the application host to block requests targeting private IP ranges and cloud metadata endpoints (e.g., 169.254.169.254). Alternatively, block external traffic or enforce strict authentication for the `/api/metatags` edge endpoint at the reverse proxy or API gateway level.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery