GHSA-hf86-8x8v-h7vc

Suggest an improvement
Source
https://github.com/advisories/GHSA-hf86-8x8v-h7vc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-hf86-8x8v-h7vc/GHSA-hf86-8x8v-h7vc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hf86-8x8v-h7vc
Aliases
Published
2025-08-20T09:30:41Z
Modified
2025-08-20T20:28:37Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
Details

Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read or update internal resources. Users are recommended to upgrade to version 1.12.0 or use the master branch, which fixes this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-08-20T19:09:23Z",
    "nvd_published_at":  "2025-08-20T09:15:27Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.apache.eventmesh:eventmesh-runtime

Package

Name
org.apache.eventmesh:eventmesh-runtime
View open source insights on deps.dev
Purl
pkg:maven/org.apache.eventmesh/eventmesh-runtime

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.0-release
Last Affected
1.11.0-release

Affected versions

1.*
1.6.0-release
1.7.0-release
1.8.0-release
1.9.0-release
1.10.0-release
1.11.0-release

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-hf86-8x8v-h7vc/GHSA-hf86-8x8v-h7vc.json"