PatchSiren

opengoofy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM opengoofy CVE published 2026-09-16

CVE-2026-92569

CVE-2026-92569 is a server-side request forgery vulnerability in Hippo4j through 1.5.0. Four ThreadPoolController endpoints fail to validate the clientAddress parameter, allowing authenticated attackers to supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks and cloud metadata services. This vulnerability can lead to potential unauthorized access to internal networks, [truncated]