Mmastodon TechnologyCybersecurity first seen 2 h ago, last 2 h ago, peak #11
NextChat vulnerability allows unauthenticated SSRF attacks
Original: 🔴 NextChat CVE-2026-105238 — CVSS 7.3 SSRF Single unauthenticated request → server fetches any internal URL or cloud met
A newly disclosed vulnerability, CVE-2026-105238, affects NextChat and carries a CVSS score of 7.3. Security researchers report a server-side request flaw that lets a single unauthenticated request make the server fetch arbitrary internal URLs or cloud metadata endpoints, bypassing access-code protection. No patched version has been confirmed; mitigations include blocking the x-base-url header at reverse proxies and restricting server egress.
Why now: Security teams are sharing the flaw because it exposes NextChat deployments to cloud credential theft and there is no confirmed patch yet.
Evidence
- 🔴 NextChat CVE-2026-105238 — CVSS 7.3 SSRF Single unauthenticated request → server fetches any internal URL or cloud metadata endpoint (169.254.169.254). Access-code protection bypassed. No patched version confirmed. Fix: block x-base-url at reverse proxy + restrict egress. →… · threataft@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1129375