
🚨 High/Critical - Terrascan Server Mode SSRF & Data Exposure (CVE-2026-47356, CVE-2026-47357, CVE-2026-47358) Terrascan v1.18.3 and prior exposes multiple unauthenticated SSRF vectors in server mode, allowing attackers to submit crafted scan requests or IaC templates that force the server to fetch arbitrary attacker-controlled URLs. In some cases this leads to file:// access, credential exfiltration via ~/.netrc, and leakage of full scan results to attacker endpoints via webhook callbacks. ⚠️ Affected: Terrascan ≤ 1.18.3 (server mode, unauthenticated) ❗ Status: Project archived (no fix will be released) 👉 Impact: • SSRF to internal/external services • Local file read via go-getter / template resolution • Credential leakage via netrc handling • Full scan result exfiltration via webhook_url 👉 Mitigation: • Do NOT expose Terrascan server mode publicly • Restrict to authenticated internal use only or disable server mode entirely • Replace with maintained tooling where possible
Post summary
The text announces several high‑severity Terrascan server‑mode SSRF vulnerabilities (CVE‑2026‑47356/57/58), describing their technical effects and providing mitigation guidance, but does not mention a PoC, active exploitation, or a vendor patch.

