{"id":"CVE-2026-88403","title":"A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.","summary":"A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.","severity":"none","published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T21:17:14.390","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88403","references":[{"url":"https://github.com/czx1111/cve/issues/7","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-21T20:52:58.295Z","slug":"CVE-2026-88403","body":"## Overview\n\nA Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}