CVE-2026-65924
EUVD-2026-4957827.07.2026, 20:16
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jfrog | artifactory | 𝑥 < 7.111.18 | CNA |
| jfrog | artifactory | 7.117.0 ≤ 𝑥 < 7.117.25 | CNA |
| jfrog | artifactory | 7.125.0 ≤ 𝑥 < 7.125.18 | CNA |
| jfrog | artifactory | 7.133.0 ≤ 𝑥 < 7.133.27 | CNA |
| jfrog | artifactory | 7.146.0 ≤ 𝑥 < 7.146.34 | CNA |
| jfrog | artifactory | 7.161.0 ≤ 𝑥 < 7.161.15 | CNA |