漏洞情报聚合

CVE-2026-15378 - A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as servi - 漏洞详情

漏洞编号:CVE-2026-15378

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-15378

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-918

发布/更新时间:2026-07-10 / 2026-08-27

漏洞描述

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.

相关链接

相关漏洞

« 返回首页