THREAT OPS › Threat News › [NVD] CVE-2026-67620 (HIGH 7.7) — Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, al
[NVD] CVE-2026-67620 (HIGH 7.7) — Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, al
CVE-2026-67620 CVSS: 7.7 HIGH Published: 2026-08-08T16:16:49.420
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67620cve
- 192.0.0.192ipv4
- 100.100.100.200ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67620