๐Ÿ” CVE Alert

CVE-2026-67346

HIGH 8.6

Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials.

CWE CWE-918
Vendor kyegomez
Product swarms
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for kyegomez swarms

Be the first to know when new high vulnerabilities affecting kyegomez swarms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

kyegomez / swarms
0 โ‰ค 6.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kyegomez/swarms/issues/1714 github.com: https://github.com/kyegomez/swarms/pull/1734 github.com: https://github.com/kyegomez/swarms/commit/8b0fc9e4645603ad94d5fcf4da86e3b9c71f4743 vulncheck.com: https://www.vulncheck.com/advisories/swarms-server-side-request-forgery-via-dns-rebinding-bypass

Credits

George Chen