← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 1, 2026 · 18:09via CVEFeed

CVE-2026-8712 - Wyoming 1.10.2 SSRF via uri Query Parameter

Brief

CVE ID : CVE-2026-8712

Published : Sept. 1, 2026, 6:09 p. m.

  • 1 hour, 7 minutes ago

Description : Wyoming before 1.

  • 2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API.

Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts.

Severity: 8.3

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed