Back to VulnFeed / CVE-2026-7605
root@hackertop:~/vulnfeed/CVE-2026-7605#
CVE-2026-7605 MEDIUM SSRF ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

JeecgBoot up to 3.9.1 uploadImgByHttpEndpoint CommonController.java server-side request forgery

JeecgBoot 20d ago Impact pending confirmation
LIFECYCLE
5.7 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability has been found in JeecgBoot up to 3.9.1 and classified as critical. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the component uploadImgByHttpEndpoint. Upgrading eliminates this vulnerability. The upgrade is hosted for download at github.com.
Root Cause Analysis
The CWE definition for the vulnerability is CWE-918. The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Impact: As an impact it is known to affect confidentiality, integrity, and availability.

Exploit: It is possible to download the exploit at github.com. It is declared as proof-of-concept. The vendor confirmed the issue and will provide a fix in the upcoming release.

Countermeasure: Upgrading eliminates this vulnerability. The upgrade is hosted for download at github.com.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7605 · CVSS 5.7 · Active Threat