CVE-2026-42864Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]). Its attachments payload is fetched server-side via httpx.get() with no URL validation, then uploaded as an attachment on the Jira ticket that gets created. An unauthenticated caller able to reach the ingress can coerce the pod into fetching arbitrary URLs and exfiltrate the response as a Jira attachment. On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. This vulnerability is fixed in 0.0.54.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 205-11
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42864 FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authe… https://www.cve.org/CVERecord?id=CVE-2026-42864

    Post summary

    The text discloses that FireFighter versions before 0.0.54 have an unauthenticated POST endpoint (/api/v2/firefighter/raid/jira_bot), revealing an access vulnerability.

    0000055
    57.5K followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 Entity detected unauthenticated SSRF in FireFighter <0.0.54 (CVE-2026-42864). Endpoint /api/v2/firefighter/raid/jira_bot lacks auth, allows arbitrary URL fetch. On EC2/EKS without IMDSv2: IAM credential theft. Upgrade to 0.0.54. https://0x2ed3bb60.xyz/threat/363b8efead572a32

    Post summary

    An unauthenticated SSRF vulnerability (CVE-2026-42864) in FireFighter versions below 0.0.54 can lead to arbitrary URL fetch and IAM credential theft; users should upgrade to 0.0.54 to mitigate.

    0000028
    7 followersView on X

Explore more