Executive brief
Jina Reader is a service that converts web pages into LLM-friendly text by fetching and processing URLs. The vulnerability disables its protection against accessing private internal networks when the service is deployed outside Google Cloud, allowing attackers to craft URLs that resolve to internal IP addresses and retrieve sensitive cloud metadata and internal service data without authentication.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw in the URL validation logic of jina-ai/reader. The root cause lies in a conditional check that only enforces private-address filtering when both production mode is enabled AND a Google Cloud project is configured. Attackers outside Google Cloud deployments can bypass the private-address guard by supplying publicly resolvable DNS hostnames that map to private IP ranges (RFC 1918), allowing them to reach internal cloud metadata services, internal APIs, and other non-public resources. The vulnerable code path is in src/services/misc.ts where the `privateIpNotAcceptable` flag gates both direct IP and DNS-resolved private IP blocking. Attack requires only network-level access to the Jina Reader endpoint; no authentication is required.
Affected products
- Jina AI Reader Affected versions prior to patch
Timeline
- 2026-08-30: disclosed: Vulnerability disclosed via NVD as CVE-2026-82638
- 2026-08-30: other: Public advisory and GitHub repository reference available