THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8g4w-4ffg-8vgx (high) — 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

[GHSA] GHSA-8g4w-4ffg-8vgx (high) — 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

highgithub_advisoriesPublished 2026-08-17

GHSA-8g4w-4ffg-8vgx Severity: high CVE: CVE-2026-56677

9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

### Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in the 9Router dashboard via the `/api/auth/oidc/test` endpoint. The application accepts a user-controlled URL string through the `issuerUrl` parameter and performs an outbound HTTP

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8g4w-4ffg-8vgx