CVE-2026-13316
published 2026-06-30CVE-2026-13316: A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and…
PriorityP420medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.10%
1.2th percentile
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | 6.0 – 6.19 | — |
| satellite-utils_el8 | foreman | — | — |
| theforeman | foreman | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files.
ghsa_unreviewed·2026-06-30
CVE-2026-13316 [MEDIUM] CWE-918 A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files.
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
VulDB
Red Hat Satellite 6 HTTP Parameter /GCP/Azure server-side request forgery (EUVD-2026-40281)
vuldb·2026-06-30·CVSS 4.4
CVE-2026-13316 [MEDIUM] Red Hat Satellite 6 HTTP Parameter /GCP/Azure server-side request forgery (EUVD-2026-40281)
A vulnerability marked as critical has been reported in Red Hat Satellite 6. Impacted is an unknown function of the file /GCP/Azure of the component HTTP Parameter Handler. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-13316. It is possible to initiate the attack remotely. There is no exploit available.
Red Hat
Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config
vendor_redhat·2026-06-18·CVSS 4.4
CVE-2026-13316 [MEDIUM] CWE-918 Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config
Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Statement: Red Hat Product Security has assessed that this issue is not exploitable under the default configuration. Exploitation requires an attacker with sufficient privileges on the host where Foreman is installed to modify the relevant configuration files and to trigger the Server-Side Request Forgery (SSRF) condition.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Secur
No detection rules found.
No public exploits indexed.
2026-06-30
Published