Vulnerability Bulletins

CVE-2026-13316

   
Affected software AWS
 
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-13316