Junglewise Threat Intelligence

CVE-2026-90486: openstatusHQ openstatus server-side request forgery in domain rewrite

CVE-2026-90486 · Severity: medium · CVSS 6.3 · Published 2026-09-12

Executive brief

openstatusHQ openstatus is a status page and uptime monitoring platform. A server-side request forgery (SSRF) vulnerability in the custom domain rewriting component allows remote attackers to make unauthorized requests from the server to internal or external systems, potentially exposing sensitive data or enabling further attacks on backend infrastructure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The vulnerable component fails to properly validate or sanitize custom domain rewrite configurations, allowing an attacker to craft malicious requests that cause the server to make HTTP requests to unintended targets. The attack is remotely exploitable without authentication or special preconditions. Successful exploitation enables attackers to access internal services, metadata endpoints, or external systems that should not be directly reachable from the internet. The issue was addressed via a silent patch (commit 86f370c9c), and the openstatus project uses a rolling release model.

Affected products

  • openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265

Timeline

  • 2026-09-12: disclosed: Advisory published
  • 2026-08-16: patched: Silent patch applied (commit 86f370c9c20074c3c3fdec53a359874b8e670fd4)

References