SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-61422

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache CloudStack is vulnerable to an authenticated pre-validation Server-Side Request Forgery (SSRF) during the template and ISO registration process, where live HTTP HEAD/GET calls are made before URL validation. While this does not allow for malicious template or ISO registration, it could potentially lead to unintended information disclosure or resource consumption. Organizations using affected versions (4.20.3.0, 4.21.0.0 to 4.22.1.0) should prioritize upgrading to versions 4.20.3.1 or 4.22.1.1 or later to mitigate this vulnerability.

CVE
CVE-2026-61422
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%
Apache

Original NVD Description

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicious template or ISO registration risk, as URL validation still occurs prior to the actual download by the Secondary Storage VM.This issue affects Apache CloudStack: in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)