
CVE-2026-27818: Close But No Cigar: The TerriaJS SSRF Suffix Bypass A classic string validation error in the TerriaJS-Server proxy controller allowed attackers to bypass domain allowlists. By relying on a primitive `indexOf` check to validate hostname... https://cvereports.com/reports/CVE-2026-27818
Post summary
The post discloses a string validation flaw in TerriaJS‑Server that enables an SSRF suffix bypass via an `indexOf` check, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

