Junglewise Threat Intelligence

CVE-2026-42864: ManoManoTech FireFighter SSRF and missing authentication in Jira bot endpoint

CVE-2026-42864 · Severity: critical · CVSS 9.9 · Published 2026-05-11

Vendors: PyPI.

Executive brief

FireFighter, an incident management tool, contains a security flaw in its Jira integration component. An unauthenticated attacker can exploit this to force the application to make requests to internal systems, potentially stealing sensitive AWS cloud credentials. This could lead to a full compromise of the cloud environment where the application is hosted.

Technical details

The `POST /api/v2/firefighter/raid/jira_bot` endpoint in the `firefighter-incident` package fails to enforce authentication despite documentation suggesting otherwise. The `attachments` parameter is processed by `httpx.get()` without URL validation or destination filtering. An unauthenticated remote attacker can provide a URL pointing to the AWS Instance Metadata Service (IMDSv1) at `169.254.169.254`. The application fetches the metadata and uploads it as an attachment to a Jira ticket, effectively exfiltrating temporary IAM credentials. This is fixed in version 0.0.54 by enforcing `IsAuthenticated` permissions and implementing strict URL validation that rejects private, loopback, and link-local IP ranges.

Affected products

  • ManoManoTech firefighter-incident < 0.0.54

Timeline

  • 2026-04-24: patched: Fix committed to repository
  • 2026-05-05: disclosed: GitHub Advisory published
  • 2026-05-11: advisory: NVD published CVE-2026-42864

References