{"id":"CVE-2026-91081","title":"Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID","summary":"Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-tim…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-918"],"vendor":"suitenumerique","product":"docs","affected":["docs <= 5.6.1"],"published":"2026-09-14","updated":"2026-09-20","sourceUpdated":"2026-09-20T01:16:33.307","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91081","references":[{"url":"https://github.com/suitenumerique/docs","label":"disclosure@vulncheck.com"},{"url":"https://github.com/suitenumerique/docs/blob/v5.6.1/src/backend/core/api/viewsets.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/suitenumerique/docs/blob/v5.6.1/src/backend/core/models.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/suitenumerique/docs/issues/2545","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/docs-through-5.6.1-ssrf-via-unauthenticated-cors-proxy-endpoint","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-20T00:13:42.673520Z"},"epss":0.00248,"epssPercentile":0.16457,"ingestedAt":"2026-09-14T19:13:23.464Z","slug":"CVE-2026-91081","body":"## Overview\n\nDocs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}