CVE-2026-21512
EUVD-2026-736110.02.2026, 18:16
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | azure_devops_server | 𝑥 < 2022.2.0 |
| microsoft | azure_devops_server | 2022.2.0 |
| microsoft | azure_devops_server | 2022.2.0:patch2 |
| microsoft | azure_devops_server | 2022.2.0:patch3 |
| microsoft | azure_devops_server | 2022.2.0:patch4 |
| microsoft | azure_devops_server | 2022.2.0:patch5 |
| microsoft | azure_devops_server | 2022.2.0:patch6 |
| microsoft | azure_devops_server | 2022.2.0:patch7 |
| microsoft | azure_devops_server | 2022.2.0:rc |
𝑥
= Vulnerable software versions