CVE-2026-4528Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-22); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-21: 1Mentions · 2026-03-22: 5Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 403-2103-2203-23
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-211
General1
2026-03-225
Disclosure5
2026-03-231
General1
Full discourse7 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20131 2 - CVE-2026-22898 3 - CVE-2014-4113 4 - CVE-2026-4528 5 - CVE-2022-43555 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely names five trending CVEs without providing any proof of concept, exploitation details, patches, or technical specifics.

    01020129
    1.7K followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    CVE-2026-4528 affects trueleaf ApiFlow version 0.9.7. Vulnerability sits in the validateUrlSecurity function within the URL Validation Handler. Enables server-side request forgery through manipulation.

    Post summary

    CVE-2026-4528 is a server‑side request forgery vulnerability in trueleaf ApiFlow 0.9.7’s validateUrlSecurity function, allowing attackers to manipulate URL validation for malicious requests.

    100005
    14 followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    🚨 Today CVE: CVE-2026-4528 This is where detection makes the difference. Another SSRF in URL validation logic. Same function name we've seen break before.

    Post summary

    The post announces the CVE-2026-4528 vulnerability, specifying it as an SSRF flaw in URL validation logic, but provides no PoC, exploit, patch, or evidence of active exploitation.

    100007
    14 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4528 A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_pr… https://www.cve.org/CVERecord?id=CVE-2026-4528

    Post summary

    Acknowledges CVE‑2026‑4528, identifies the affected validateUrlSecurity function in trueleaf ApiFlow 0.9.7, but offers no PoC, exploitation, patch, or evidence of active attacks.

    0000059
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4528 - trueleaf - ApiFlow - https://www.redpacketsecurity.com/cve-alert-cve-2026-4528-trueleaf-apiflow/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4528 #trueleaf #apiflow

    Post summary

    The tweet announces a CVE-2026-4528 vulnerability for trueleaf ApiFlow, linking to an alert page, but provides no further technical or operational details.

    0000053
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4528 - trueleaf ApiFlow URL Validation http_proxy.service.ts validateUrlSecurity server-side request forgery Intel Report: https://ift.tt/RBSeEbM

    Post summary

    The alert announces CVE‑2026‑4528 as a server‑side request forgery issue in trueleaf’s ApiFlow validateUrlSecurity, but provides no PoC, exploit, or patch information.

    0000025
    291 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4528 Server-Side Request Forgery in trueleaf ApiFlow 0.9.7 URL Validation Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4528

    Post summary

    A brief mention of CVE-2026-4528 is presented, including its name and a link to a vulnerability details page, but no further technical details, PoC, or mitigation are provided.

    0000032
    4.0K followersView on X

Explore more