Executive brief
Keep, an open-source AIOps and alert management platform, contains a security flaw in its health check feature. An unauthenticated attacker can trick the system into making unauthorized network requests to internal services or cloud management interfaces. This could allow an attacker to steal sensitive cloud credentials, map out private internal networks, or access data that is not intended to be public.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `POST /providers/healthcheck` endpoint of Keep due to a lack of authentication and insufficient input validation. Unlike other provider routes, this endpoint does not implement the `IdentityManagerFactory.get_auth_verifier` dependency, allowing unauthenticated access. An attacker can supply a malicious JSON payload containing a controlled 'host' parameter. The backend then uses the `requests` library to perform outbound GET requests to the provided host (e.g., targeting 169.254.169.254 or internal loopback addresses) to validate provider scopes. This enables internal network reconnaissance and the potential theft of cloud instance metadata credentials. The vulnerability is present in commit 91c75e0 and earlier versions.
Affected products
- keephq Keep commit 91c75e0 and earlier
Timeline
- 2026-06-09: disclosed: Initial report to maintainers via GitHub Security Advisory
- 2026-07-13: other: Public issue opened on GitHub due to lack of response
- 2026-07-21: advisory: NVD and VulnCheck advisory published