CVE-2026-24902Patch(adguard / trusttunnel)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adguard trusttunnel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The `TcpDestination::Address(peer) => peer` path proceeded to `TcpStream::connect()` without equivalent checks (for example `is_global_ip`, `is_loopback`), allowing loopback/private targets to be reached by supplying a numeric IP. The vulnerability is fixed in version 0.9.114.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trusttunnel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
trusttunnel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 101-2901-30
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-291
Patch1
2026-01-301
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24902 Server-Side Request Forgery in TrustTunnel VPN Protocol Before 0.9.114 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24902

    Post summary

    The text announces CVE-2026-24902 as a Server‑Side Request Forgery vulnerability in TrustTunnel VPN Protocol versions prior to 0.9.114, without noting PoC, exploits, or patch details.

    00000115
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-24902 TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forward… https://www.cve.org/CVERecord?id=CVE-2026-24902

    Post summary

    TrustTunnel before 0.9.114 can be exploited via SSRF and private‑network bypass; updating to 0.9.114 removes the vulnerability.

    00000303
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadguardtrusttunnel---

Explore more