CVE-2026-9813 Details
Description
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, or other restricted network resources, potentially enabling interaction with internal services or cloud metadata endpoints from the server's network context.
A server-side request forgery (SSRF) vulnerability has been identified in FlowIntel versions prior to 3.3.0. The issue arises in the external reference URL probe functionality within app/case/task.py. This vulnerability allows an attacker who can submit an external reference URL to manipulate the application server into sending an HTTP HEAD request to a destination of their choice. The vulnerability is rooted in inadequate validation of the URL scheme and the resolved destination address, which may permit requests to loopback, link-local, private, reserved, or other restricted network resources. Such interactions could potentially access internal services or cloud metadata endpoints from the server's network context.
Users can update to FlowIntel version 3.3.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/flowintel/flowintel/commit/68b523b47854c54bf36fd706c0fd5353063b5409 | CIRCL | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| flowintel flowintel | < 3.3.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CIRCL |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | CIRCL |