Server-Side Request Forgery (CVE-2026-86539) Impacts 'knowns' Software Through Version 0.33.0
A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-86539, has been reported in 'knowns' software up to version 0.33.0. The vulnerability in the POST /api/embedding-models/test endpoint allows unauthenticated attackers to issue outbound requests to arbitrary destinations, potentially enabling internal host enumeration and cloud metadata endpoint exploitation.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai