{"id":"CVE-2026-82477","title":"In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint","summary":"In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","cwe":["CWE-918"],"published":"2026-08-29","updated":"2026-08-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82477","references":[{"url":"https://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b485937b","label":"cve@mitre.org"},{"url":"https://github.com/mitre/heimdall2/releases/tag/v2.14.0","label":"cve@mitre.org"},{"url":"https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch","label":"cve@mitre.org"}],"tags":["nvd"],"ingestedAt":"2026-08-30T07:49:08.897Z","epss":0.00475,"epssPercentile":0.38371,"slug":"CVE-2026-82477","body":"## Overview\n\nIn MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}