CVE-2026-67436
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.
| CWE | CWE-20 CWE-200 CWE-918 |
| Vendor | linuxfabrik |
| Product | monitoring-plugins |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for linuxfabrik monitoring-plugins
Be the first to know when new unknown vulnerabilities affecting linuxfabrik monitoring-plugins are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linuxfabrik / monitoring-plugins
<= 6.0.0