CVE-2026-56676Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy can use a vision-capable model and an attacker-controlled DNS name that first resolves to a public IP and then rebinds to an internal address, allowing server-side requests to internal-only HTTP services. This issue is fixed in version 0.5.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 3Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 307-10
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - 9Router DNS-Rebinding SSRF in Image Fetch (CVE-2026-56676) 9Router validates image URLs by resolving the host before fetching, but its server-side image fetch (image.js) does a separate DNS resolution later. That TOCTOU gap enables DNS rebinding: an authenticated proxy user with a vision-capable model supplies an attacker-controlled DNS name that first resolves to a public IP (passing the check), then rebinds to an internal address at fetch time. The result is server-side requests to internal-only HTTP services (SSRF) despite the URL validation. It's the classic check-then-use DNS rebinding pattern. 👉Upgrade 9Router to 0.5.2.

    Post summary

    CVE-2026-56676 exploits a TOCTOU DNS rebinding flaw in 9Router’s image fetch, enabling SSRF. Upgrading to version 0.5.2 resolves the vulnerability.

    0000096
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56676 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js p… https://www.cve.org/CVERecord?id=CVE-2026-56676 ----- Traducción: CVE-2026-56676 9Ro… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-56676, noting that prior to version 0.5.2 9Router validates image URLs by resolving hosts before fetching, and includes a link to the CVE record.

    0000043
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-56676 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js p… https://www.cve.org/CVERecord?id=CVE-2026-56676

    Post summary

    The post references CVE‑2026‑56676, noting a URL‑validation issue in version 0.5.2 of 9Router, but offers no evidence of PoC, exploit, or mitigation, and provides only limited technical context.

    00000617
    57.8K followersView on X

Explore more