CVE-2026-5936Disclosure(foxit / pdf_services_api)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch foxit pdf_services_api systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_services_api

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
pdf_services_api

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-13: 4Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 404-13
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5936 An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be e… https://www.cve.org/CVERecord?id=CVE-2026-5936

    Post summary

    The text reports CVE‑2026‑5936 as a server‑side request forgery that can be triggered by a crafted URL, but it lacks a PoC, exploit details, active exploitation evidence, or mitigation information.

    00010122
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5936 Server-Side Request Forgery Enabling Arbitrary HTTP Requests and Network Access Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5936

    Post summary

    A new SSRF vulnerability (CVE-2026-5936) is disclosed, allowing arbitrary HTTP requests and network access bypass, with basic details referenced via a vulnerability details link.

    0000047
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    ```json { "x": "🚨 HIGH SEVERITY: CVE-2026-5936 (CVSS 8.5)\n\nServer-Side Request Forgery (SSRF) allows attackers to control HTTP requests, probe internal networks & access cloud metadata services.\n\nRequires low privileges, no user interaction.\n\nPatch immediately.\n\n#CVE https://t.co/JHX59XO0lU

    Post summary

    A high‑severity SSRF vulnerability (CVE‑2026‑5936) is disclosed with CVSS 8.5 and an urgent patch recommendation; no PoC, exploit, or active exploitation is reported.

    0000037
    25 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5936: HIGH] Crafted URLs can be used by attackers to control server-side HTTP requests, leading to potential exploitation of network services, sensitive data exposure, and further internal compromise.#cve,CVE-2026-5936,#cybersecurity https://cvefind.com/CVE-2026-5936

    Post summary

    The post announces CVE‑2026‑5936 as a high‑severity issue where malicious crafted URLs can manipulate server‑side HTTP requests, potentially exposing sensitive data and enabling further internal compromise.

    0000038
    620 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_services_api---

Explore more