CVE-2026-16196

EUVD-2026-45407
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 2efbe5d560e7ed9bc5209c203dc4aa6ecdbc7405. To fix this issue, it is recommended to deploy a patch.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulDBCNA
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sipeedpicoclaw
0.2.0
CNA
sipeedpicoclaw
0.2.1
CNA
sipeedpicoclaw
0.2.2
CNA
sipeedpicoclaw
0.2.3
CNA
sipeedpicoclaw
0.2.4
CNA
sipeedpicoclaw
0.2.5
CNA
sipeedpicoclaw
0.2.6
CNA
sipeedpicoclaw
0.2.7
CNA
sipeedpicoclaw
0.2.8
CNA
sipeedpicoclaw
0.2.9
CNA