MEDIUM
CVE-2026-91081
CVSS
5.8
Description
Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.25%
Probability of exploitation in next 30 days
16.5th percentile
References
https://github.com/suitenumerique/docs
https://github.com/suitenumerique/docs/blob/v5.6.1/src/backend/core/api/viewsets.py
https://github.com/suitenumerique/docs/blob/v5.6.1/src/backend/core/models.py
https://github.com/suitenumerique/docs/issues/2545
https://www.vulncheck.com/advisories/docs-through-5.6.1-ssrf-via-unauthenticated-cors-proxy-endpoint
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.