# CVE-2026-47160

## Summary

- **CVE ID:** CVE-2026-47160
- **Severity:** MEDIUM
- **CVSS Score:** 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)
- **CWE:** CWE-918, CWE-1389
- **Published:** Jul 15, 2026
- **Last Modified:** Jul 15, 2026

## Description

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP client for blind internal network or port discovery. This issue is fixed in version 1.36.0.

## Affected Products

- dani-garcia — vaultwarden (< 1.36.0)

## References

- [CNA](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-72vh-x5jq-m82g)
- [CNA](https://github.com/dani-garcia/vaultwarden/pull/7162)
- [CNA](https://github.com/dani-garcia/vaultwarden/commit/a354e57659d26149fde0d91b76f83fce94e8f277)
- [CNA](https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._