Geng Yang[verified]@geng_zastDisclosure
ZAST.AI identified a new SSRF vulnerability (CVE-2026-3733) in XXL-JOB where an admin trigger field can be used as a live remoting destination, enabling SSRF attacks.
ZAST AI[verified]@zast_aiDisclosure
ZAST identified its SSRF vulnerability (CVE-2026-3733) in XXL-JOB, noting that the admin trigger flow accepts an addressList and uses it to make outbound server requests, creating a potential SSRF path.
CVE@CVEnewDisclosure
A new vulnerability (CVE‑2026‑3733) has been identified in xuxueli xxl‑job up to version 3.3.2, affecting an unspecified function in the JobInfo controller, with no further details or patches disclosed.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces a newly disclosed CVE‑2026‑3733 affecting xuxueli xxl‑job, identified as a server‑side request forgery, with an Intel report link but no evidence of exploitation, PoC, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a new SSRF vulnerability (CVE‑2026‑3733) affecting XXL‑Job Admin Controller prior to version 3.3.2, providing basic technical details but no PoC, exploit, or mitigation information.