CVE-2026-42352High· 8.6▾ Twilightpygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
OGC API - Process execution requests can use the subscriber object to requests to internal HTTP services.
The issue has been patched in master branch and made available as part of the 0.23.3 release. The patch disables any HTTP requests made to internal resources by default (unless explicitly defined in configuration by a new allow_internal_requests directive.
The commit/fix can be found in 3a63f5b0cc6275e3ae0edb47726b13a43cdd90ef.
Users can update existing applications by disabling process based resources in their pygeoapi config, until 0.23.3 can be installed and deployed.
pygeoapi >= 0.23.0, < 0.23.3Upgrade to a patched release:
pygeoapi 0.23.3Connected by shared product, vendor, weakness, or advisory.