Junglewise Threat Intelligence

CVE-2026-2053: WSO2 API Manager SSRF in WS-Addressing headers

CVE-2026-2053 · Severity: high · CVSS 8.3 · Published 2026-06-26

Technologies: Wso2 API Manager. Vendors: Wso2.

Executive brief

WSO2 API Manager is a platform used by organizations to create, manage, and secure digital interfaces (APIs). A security flaw in how the system handles certain message headers allows an attacker to force the server to make unauthorized requests to internal systems. This could allow an outsider to bypass firewall protections and access sensitive internal data or services that are not intended to be public.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the WSO2 API Manager message flow component due to insufficient validation of WS-Addressing headers. In specific configurations where custom handlers or global Synapse handlers trigger message building early in the mediation sequence, the system processes user-controlled WS-Addressing headers to determine outbound request destinations. An unauthenticated remote attacker can exploit this by supplying crafted header values to redirect server-initiated requests toward internal network resources. The vulnerability affects versions 3.1.0 through 4.2.0; fixes are available via specific update levels for each version or by migrating to the latest unaffected release.

Affected products

  • WSO2 API Manager 3.1.0 before update 360, 3.2.0 before update 465, 3.2.1 before update 84, 4.0.0 before update 385, 4.2.0 before update 189

Timeline

  • 2026-05-03: advisory: Initial advisory published by WSO2
  • 2026-06-26: disclosed: CVE published to NVD dataset

References

Related threats