CVE-2026-57573Patch(kidocode / crawl4ai)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch kidocode crawl4ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with crawler_config.stream=true with a URL pointing at an internal, private, or link-local address; the server fetched it and streamed the response body back. This issue is fixed in version 0.9.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-08: 2Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 207-08
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-57573 - #SSRF in #Crawl4AI #Docker #API. Streaming paths skip destination validation. Unauthenticated remote access to internal networks. #CVSS 8.6. No patch available. Mitigate immediately. #CVE #infosec #k8s #devops #devsecops #sysadmin #kubernetes https://www.valtersit.com/cve/CVE-2026-57573/

    Post summary

    This post highlights a high‑severity SSRF vulnerability (CVE‑2026‑57573) in Crawl4AI Docker API that allows unauthenticated remote access to internal networks, with no patches available and urgent mitigation required.

    0000057
    974 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-57573 (CVSS 8.6) Crawl4AI Docker API SSRF flaw allows unauthenticated attackers to access internal networks via streaming endpoint. Affects versions <0.9.0. ✅ Patch to v0.9.0 immediately #CVE #Vulnerability #PatchNow https://t.co/cB8HEuwz5W

    Post summary

    CVE-2026-57573 is a high‑severity SSRF vulnerability in Crawl4AI Docker API affecting versions below 0.9.0; an immediate patch to v0.9.0 is available.

    0000053
    68 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more