MEDIUM
opengoofy
CVE published 2026-09-16
CVE-2026-92569
CVE-2026-92569 is a server-side request forgery vulnerability in Hippo4j through 1.5.0. Four ThreadPoolController endpoints fail to validate the clientAddress parameter, allowing authenticated attackers to supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks and cloud metadata services. This vulnerability can lead to potential unauthorized access to internal networks, [truncated]