CVE-2026-5259 Details
Description
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
A server-side request forgery (SSRF) vulnerability has been identified in AutohomeCorp Frostmourne versions prior to 1.0. The issue resides in the Alarm Preview component, specifically within the AlarmController.java file. This vulnerability allows authenticated users to send arbitrary HTTP or HTTPS requests from the server, bypassing URL validation. The response from these requests is returned directly to the user, which could be exploited to access internal network resources, cloud metadata endpoints, or perform port scanning.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 1, 2026CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fx4tqqfvdw4.feishu.cn/docx/GE4GdxBxKoSvBOxhkTRcsawlnhc?from=from_copylink | [email protected] | ExploitPartial Content |
| https://vuldb.com/submit/780669 | [email protected] | Technical Description |
| https://vuldb.com/vuln/354449 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/354449/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutohomeCorp frostmourne | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |
Volerion