Intel

AIKIDO-2026-10633

github.com/aixgo-dev/aixgo is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 29, 2026

60

Medium Risk

This Affects:

GOgithub.com/aixgo-dev/aixgo
0.3.0 - 0.7.2
Fixed in 0.7.3
Are you affected? Scan for Free

TL;DR

SIEM backends in pkg/security/audit_siem.go constructed HTTP clients using a transport that could allow SSRF vectors such as DNS rebinding and redirect-based URL changes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/aixgo-dev/aixgo is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.3.0 - 0.7.2.

How to fix this

Upgrade the github.com/aixgo-dev/aixgo library to the patch version.