Junglewise Threat Intelligence

CVE-2026-55414: NL Portal Backend Libraries SSRF in form resolver

CVE-2026-55414 · Severity: medium · CVSS 5.3 · Published 2026-06-19

Technologies: NL Portal Backend Libraries. Vendors: Maven, NL Portal.

Executive brief

The NL Portal backend libraries contain a vulnerability where certain public web services for retrieving form definitions do not properly validate user-supplied web addresses. An unauthenticated attacker can trick the system into sending a privileged security token to a different location on the same server. While the impact is limited to the same server host, it could potentially lead to the exposure of sensitive internal access tokens if the server hosts other attacker-accessible services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the GraphQL resolvers `getFormDefinitionByObjectenApiUrl` and `getFormDefinitionById`. These resolvers are unauthenticated by design but fail to properly validate the `url` argument before fetching it using a privileged Objecten-API token. While a host-equality guard exists, it lacks checks for scheme, port, or path, allowing an attacker to redirect the request (and the attached Authorization header) to any endpoint on the configured Objecten-API host. The vulnerability is mitigated by the fact that the token is only sent to the configured host and responses are strictly deserialized into specific form-definition types, preventing arbitrary data exfiltration. The issue was fixed in version 3.0.4 by removing the vulnerable resolvers and implementing UUID-based lookups.

Affected products

  • NL Portal nl-portal-backend-libraries >= 1.1.0, < 3.0.4

Timeline

  • 2023-10-31: other: Vulnerability first shipped in 1.1.0.RELEASE
  • 2026-06-18: advisory: GitHub Advisory published
  • 2026-06-19: disclosed: CVE-2026-55414 assigned

References

Related threats