pdnuclei-bot@pdnuclei_botDisclosure
A critical SSRF flaw (CVE-2026-33340) in LoLLMs WEBUI is disclosed with a linked resource, but no exploit code, active exploitation, or patch information is provided.
The Hacker Wire@TheHackerWireDisclosure
A critical SSRF vulnerability (CVE‑2026‑33340) was disclosed for LoLLMs WEBUI, with technical details highlighted but no active exploitation, PoC, or patch information provided.
CVE@CVEnewDisclosure
A critical SSRF vulnerability disclosed in LoLLMs WEBUI; no PoC, exploit, or active exploitation mentioned.
CVEFind.com@CveFindComDisclosure
A critical SSRF vulnerability in LoLLMs Web UI that permits unauthenticated attackers to reach internal services has been disclosed, with no patch or workaround currently available.
0day Signal@0dayPublishingDisclosure
The post announces an unauthenticated SSRF vulnerability in LoLLMs' `/api/proxy` endpoint that enables cloud metadata theft and network pivot, providing technical details but no PoC, exploit, patch, or active exploitation evidence.