CVE-2026-56266 Details
Description
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.
A server-side request forgery (SSRF) vulnerability has been identified in Crawl4AI versions prior to 0.8.7. This vulnerability exists in the main crawl endpoints, including '/crawl', '/crawl/stream', '/md', and '/llm'. The issue arises because these endpoints fetch user-supplied URLs without proper validation. Unauthenticated attackers can exploit this flaw by using IPv6-mapped IPv4 addresses to bypass the internal-address blocklist, potentially accessing internal services and cloud metadata endpoints.
Users are advised to upgrade to Crawl4AI version 0.8.7 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/unclecode/crawl4ai | [email protected] | Product |
| https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-direct-crawl-endpoints | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kidocode crawl4ai | < 0.8.7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |