Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > SSRF
#SSRF

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin

18 August 2026  |  dark6  |  Vulnerability

Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...

>> read more

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

Critical Next.js and React Server Components Vulnerabilities: SSRF, DoS, and Middleware Bypass Patched

9 May 2026  |  dark6  |  Vulnerability

Vercel has released a sweeping set of security advisories for Next.js addressing more than a dozen vulnerabilities including denial-of-service, SSRF via WebSocket upgrades, and middleware bypass flaws. All...

>> read more