๐Ÿ” CVE Alert

CVE-2026-31974

LOW 3.0

Blind SSRF on OpenProject instance via webhooks

CVSS Score
3.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (POST /admin/settings/mail_notifications) accepts arbitrary host and port values and exhibits measurable differences in response behaviour depending on whether the target IP exists and whether the port is open. An attacker with access can use these timing and error distinctions to map internal hosts and identify which services/ports are reachable. Similarly, you can create webhooks in OpenProject and point them to arbitrary IPs, resulting in the same kind of SSRF issue which allows attackers to scan the internal network. This vulnerability is fixed in 17.2.0.

CWE CWE-918
Vendor opf
Product openproject
Published Mar 11, 2026
Last Updated Mar 12, 2026
Stay Ahead of the Next One

Get instant alerts for opf openproject

Be the first to know when new low vulnerabilities affecting opf openproject are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

opf / openproject
< 17.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opf/openproject/security/advisories/GHSA-9wr7-j98g-2jh3