CVE-2026-22681
OpenViking < 0.3.4 SSRF via /api/v1/resources
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.
| CWE | CWE-918 |
| Vendor | volcengine |
| Product | openviking |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for volcengine openviking
Be the first to know when new high vulnerabilities affecting volcengine openviking are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Volcengine / OpenViking
0 < 0.3.4
References
github.com: https://github.com/volcengine/OpenViking/releases/tag/v0.3.4 github.com: https://github.com/volcengine/OpenViking/pull/1133 github.com: https://github.com/volcengine/OpenViking/commit/41e345896d247e43ab78bbcb38b4a5b1b38ef62c vulncheck.com: https://www.vulncheck.com/advisories/openviking-ssrf-via-api-v1-resources github.com: https://github.com/volcengine/OpenViking/pull/1133https://github.com/volcengine/OpenViking/pull/1133
Credits
Chia Min Jun Lennon