Junglewise Threat Intelligence

CVE-2026-55372: NukeViet SSRF via X-Forwarded-Host in server_info_update

CVE-2026-55372 · Severity: high · CVSS 7.2 · Published 2026-07-13

Technologies: NukeViet, nukeviet/nukeviet (Packagist). Vendors: NukeViet, Packagist.

Executive brief

NukeViet, a popular open-source content management system, is vulnerable to a security flaw that allows unauthorized individuals to force the server to make requests to internal or external systems. By manipulating specific web headers, an attacker can use the server as a proxy to scan internal networks or discover active services that are not normally accessible from the internet. This could lead to the exposure of internal network structure or the poisoning of cached server data, potentially affecting site performance and security.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in NukeViet due to improper validation of 'X-Forwarded-Host' and 'X-Forwarded-Proto' headers. The 'server_info_update()' function in 'includes/ini.php' uses these attacker-controlled headers to construct a URL for a cURL request without verifying them against the 'my_domains' allow-list. An attacker can bypass host sanitization by appending a slash to the port (e.g., '127.0.0.1:8081/'), which evades the regex intended to strip trailing ports. This allows unauthenticated remote attackers to perform blind, HEAD-only SSRF for internal port scanning and poisoning the 'config_ini' cache. The issue is fixed in version 4.6.00 by implementing stricter header validation and domain allow-listing.

Affected products

  • NukeViet NukeViet < 4.6.00

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: patched

References

Related threats