PatchSiren

jina-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH jina-ai CVE published 2026-08-30

CVE-2026-82638

The jina-ai reader, used for managing and querying data, has a vulnerability that allows unauthenticated attackers to perform server-side request forgery (SSRF) outside Google Cloud deployments. This occurs because the private-address guard is disabled in non-Google Cloud environments. Attackers can exploit this by providing publicly resolvable hostnames that map to private addresses, enabling them to acc [truncated]