CVE-2026-90486 Details
Description
A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
A server-side request forgery (SSRF) vulnerability has been identified in openstatusHQ openstatus versions prior to f04c827112f30a11d571ebdad3892826034d6265. The vulnerability arises from an unknown functionality in the file 'apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts', allowing remote attackers to manipulate requests and potentially access internal resources.
Users are advised to update to the latest version of openstatus, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 12, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openstatusHQ/openstatus/ | [email protected] | Source CodeVendor |
| https://github.com/openstatusHQ/openstatus/commit/86f370c9c20074c3c3fdec53a359874b8e670fd4 | [email protected] | Source CodeVendor |
| https://github.com/openstatusHQ/openstatus/pull/2551 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-90486 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/888087 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403074 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403074/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstatusHQ openstatus | <= f04c827112f30a11d571ebdad3892826034d6265 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2026 | New CVE Received | [email protected] |
Volerion