CVE-2026-47160
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP client for blind internal network or port discovery. This issue is fixed in version 1.36.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.40%
- CWE
- CWE-918, CWE-1389
- Published
- 2026-07-15
- Last modified
- 2026-07-15
Affected products
- dani-garcia vaultwarden
Weakness type
Related vulnerabilities
- CVE-2026-19233 — CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
- CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
- CVE-2026-87821 — Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch
- CVE-2026-79635 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-57866 — Apache Impala: Secrets Exfiltration via SSRF
- CVE-2026-54048 — Apache Impala: Avro Schema URL Server-Side Request Forgery
- CVE-2026-19733 — SSRF in Yordam Informatics's Library Automation System
- CVE-2026-80123 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...