No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Tue, 26 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1. | |
| Title | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | |
| Weaknesses | CWE-367 CWE-918 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T17:27:41.448Z
Reserved: 2026-04-26T13:26:14.514Z
Link: CVE-2026-42336
Updated: 2026-05-27T17:27:38.389Z
Status : Deferred
Published: 2026-05-26T21:16:37.170
Modified: 2026-05-27T19:41:21.417
Link: CVE-2026-42336
No data.
OpenCVE Enrichment
Updated: 2026-05-27T09:15:29Z