Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-2053 Details

Description

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-918Server-Side Request Forgery (SSRF)WSO2 LLC

Affected Products

ProductVersions
wso2 api manager
>= 3.1.0, < 3.1.0.360
>= 3.2.0, < 3.2.0.465
>= 3.2.1, < 3.2.1.84
>= 4.0.0, < 4.0.0.385
>= 4.2.0, < 4.2.0.189

CPE

  • cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-2053
NVD Published Date:
Jun 26, 2026
NVD Last Modified:
Jun 27, 2026
Source:
WSO2 LLC
CVE-2026-2053 Details - Not Deferred