Junglewise Threat Intelligence

CVE-2020-36851: Rob--W cors-anywhere SSRF in open proxy configuration

CVE-2020-36851 · Severity: medium · CVSS 4 · Published 2025-09-25

Executive brief

Rob--W cors-anywhere is a proxy service used to bypass browser security restrictions when making web requests. When configured as an open proxy, it allows unauthorized users to force the server to make requests to internal systems that are not meant to be accessible from the internet. This can lead to the theft of sensitive cloud credentials, access to private internal data, and potential full compromise of the cloud environment.

Technical details

The cors-anywhere proxy lacks a default deny list for RFC 1918 private IP ranges and cloud Instance Metadata Services (IMDS). An unauthenticated remote attacker can exploit this Server-Side Request Forgery (SSRF) by sending crafted requests with internal target URLs encoded in the proxy path. Because the proxy forwards arbitrary methods (including PUT) and headers, attackers can interact with IMDSv2 and internal management APIs. This can result in the retrieval of cloud IAM role credentials, access to internal-only services, and potential remote code execution depending on the reachable backend services. As of the advisory date, no official patch has been released; users must manually configure whitelists or network-level protections.

Affected products

  • Rob--W cors-anywhere All versions

Timeline

  • 2017-07-17: other: Issue opened regarding IP whitelisting feature request
  • 2020-06-10: disclosed: Initial discovery and blog post by CertiK research team
  • 2025-09-25: advisory: CVE-2020-36851 published and GHSA-9wmg-93pw-fc3g issued

References