HIGH
jina-ai
CVE published 2026-08-30
CVE-2026-82638
The jina-ai reader, used for managing and querying data, has a vulnerability that allows unauthenticated attackers to perform server-side request forgery (SSRF) outside Google Cloud deployments. This occurs because the private-address guard is disabled in non-Google Cloud environments. Attackers can exploit this by providing publicly resolvable hostnames that map to private addresses, enabling them to acc [truncated]