Junglewise Threat Intelligence

CVE-2026-65618: JFrog Artifactory SSRF via improper URL validation

CVE-2026-65618 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Technologies: JFrog Artifactory Self-Managed. Vendors: JFrog.

Executive brief

JFrog Artifactory, a repository management tool used to store and manage software packages, is affected by a security flaw in how it validates web addresses. An attacker with basic user access could exploit this to force the server to make unauthorized requests to internal systems or access sensitive cached data. This could lead to the exposure of private internal services that are not intended to be reachable from the outside network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in JFrog Artifactory due to improper URL validation when handling specific requests. An authenticated attacker with low privileges (PR:L) can exploit this flaw to make unauthorized requests from the Artifactory server. This can be used to probe internal network services that are otherwise unreachable or to expose cached response data. The vulnerability is addressed in Artifactory version 7.133.6 and later. The CNA (JFrog) assigned a CVSS v3.1 base score of 6.5.

Affected products

  • JFrog Artifactory Self-Managed < 7.133.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched: Fixed in version 7.133.6

References

Related threats