
🚨 High/Critical - Terrascan Server Mode SSRF & Data Exposure (CVE-2026-47356, CVE-2026-47357, CVE-2026-47358) Terrascan v1.18.3 and prior exposes multiple unauthenticated SSRF vectors in server mode, allowing attackers to submit crafted scan requests or IaC templates that force the server to fetch arbitrary attacker-controlled URLs. In some cases this leads to file:// access, credential exfiltration via ~/.netrc, and leakage of full scan results to attacker endpoints via webhook callbacks. ⚠️ Affected: Terrascan ≤ 1.18.3 (server mode, unauthenticated) ❗ Status: Project archived (no fix will be released) 👉 Impact: • SSRF to internal/external services • Local file read via go-getter / template resolution • Credential leakage via netrc handling • Full scan result exfiltration via webhook_url 👉 Mitigation: • Do NOT expose Terrascan server mode publicly • Restrict to authenticated internal use only or disable server mode entirely • Replace with maintained tooling where possible
Post summary
The post announces newly disclosed SSRF vulnerabilities in Terrascan up to v1.18.3, details the attack surface, and offers mitigation recommendations while noting no patch is available.

