Junglewise Threat Intelligence

CVE-2026-45561: Roxy-WI SSRF in SMON agent routes

CVE-2026-45561 · Severity: medium · CVSS 6.5 · Published 2026-06-10

Technologies: Roxy-WI. Vendors: Roxy-WI.

Executive brief

Roxy-WI, a management interface for web servers like HAProxy and Nginx, contains a security flaw that allows authenticated users to perform unauthorized network requests. An attacker could use this to access sensitive internal services or steal cloud credentials (such as AWS IAM roles) that are normally protected from the outside world. This could lead to a significant data breach or further compromise of the organization's cloud infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Roxy-WI versions 8.2.6.4 and prior within the /smon/agent/{version,uptime,status,checks}/<server_ip> routes. The application takes the 'server_ip' path component and passes it directly into a Python 'requests.get' call without validation against an allow-list or IP range filter. An authenticated attacker can provide loopback addresses (127.0.0.1), private RFC1918 addresses, or cloud metadata IP addresses (169.254.169.254) to exfiltrate sensitive information or interact with internal-only services. As of the advisory date, no official patches are available, and users are advised to implement manual IP validation checks.

Affected products

  • Roxy-WI Roxy-WI <= 8.2.6.4

Timeline

  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats