Intel

AIKIDO-2026-755806

arcadedb-integration is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-75844 Published 2 days ago

71

High Risk

This Affects:

JAVAarcadedb-integration
26.6.1 - 26.7.3
Fixed in 26.8.1
Are you affected? Scan for Free

TL;DR

IMPORT DATABASE checks a caller supplied URL in ImportSecurityValidator, then opens a new connection to the original URL string. The connection follows redirects and resolves the name again, so a redirect or a later DNS answer can reach an internal host the check already rejected, an incomplete fix for CVE-2026-54077. The fix sends the fetch through SafeHttpFetcher, which repeats the scheme and address check on every redirect hop.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and an authenticated user can run IMPORT DATABASE with a remote URL.

Background info

arcadedb-integration is vulnerable to Server-Side Request Forgery (SSRF) in versions 26.6.1 - 26.7.3.

How to fix this

Upgrade the com.arcadedb:arcadedb-integration library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform