CVE-2026-63334: CWE-918: Server-Side Request Forgery (SSRF) in jgraph drawio
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java performs the private-address check in Utils.sanitizeUrl() using one DNS resolution, while src/main/java/com/mxgraph/online/ProxyServlet.java later calls URL.openConnection() and performs a second resolution. An attacker-controlled hostname can resolve to a public address during validation and then to a private, link-local, or cloud metadata address when the connection is opened. Successful exploitation can return cloud instance metadata or responses from internal HTTP services through the proxy. This issue is fixed in version 30.2.7.
AI Analysis
Technical Summary
draw.io versions before 30.2.7 with ENABLE_DRAWIO_PROXY=1 are vulnerable to SSRF due to inconsistent DNS resolution in Utils.sanitizeUrl() and ProxyServlet.java. The first DNS resolution validates the hostname against private addresses, but a second resolution during URL.openConnection() can resolve the hostname to a private, link-local, or cloud metadata address. This discrepancy allows an attacker to bypass the private address check and retrieve internal HTTP service responses or cloud instance metadata via the proxy. The vulnerability is identified as CWE-918 (SSRF) and CWE-367 (Time-of-check Time-of-use race condition). The issue is resolved in version 30.2.7.
Potential Impact
Successful exploitation allows an unauthenticated attacker to retrieve sensitive internal HTTP service responses or cloud instance metadata by bypassing private address restrictions in the proxy. This can lead to disclosure of sensitive information from internal networks or cloud environments. The CVSS score is 6.8 (medium severity) with high confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Upgrade draw.io to version 30.2.7 or later, where this SSRF vulnerability is fixed. The fix addresses the inconsistent DNS resolution and private address validation. No other mitigation is required if the upgrade is applied.
CVE-2026-63334: CWE-918: Server-Side Request Forgery (SSRF) in jgraph drawio
Description
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java performs the private-address check in Utils.sanitizeUrl() using one DNS resolution, while src/main/java/com/mxgraph/online/ProxyServlet.java later calls URL.openConnection() and performs a second resolution. An attacker-controlled hostname can resolve to a public address during validation and then to a private, link-local, or cloud metadata address when the connection is opened. Successful exploitation can return cloud instance metadata or responses from internal HTTP services through the proxy. This issue is fixed in version 30.2.7.
CVSS v3.1
Score 6.8medium
Affected software
jgraph
drawio
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
draw.io versions before 30.2.7 with ENABLE_DRAWIO_PROXY=1 are vulnerable to SSRF due to inconsistent DNS resolution in Utils.sanitizeUrl() and ProxyServlet.java. The first DNS resolution validates the hostname against private addresses, but a second resolution during URL.openConnection() can resolve the hostname to a private, link-local, or cloud metadata address. This discrepancy allows an attacker to bypass the private address check and retrieve internal HTTP service responses or cloud instance metadata via the proxy. The vulnerability is identified as CWE-918 (SSRF) and CWE-367 (Time-of-check Time-of-use race condition). The issue is resolved in version 30.2.7.
Potential Impact
Successful exploitation allows an unauthenticated attacker to retrieve sensitive internal HTTP service responses or cloud instance metadata by bypassing private address restrictions in the proxy. This can lead to disclosure of sensitive information from internal networks or cloud environments. The CVSS score is 6.8 (medium severity) with high confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Upgrade draw.io to version 30.2.7 or later, where this SSRF vulnerability is fixed. The fix addresses the inconsistent DNS resolution and private address validation. No other mitigation is required if the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-16T14:14:24.384Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab15f9655bf5e2cf52f1e07
Added to database: 09/21/2026, 16:47:18 UTC
Last enriched: 09/21/2026, 17:01:44 UTC
Last updated: 09/22/2026, 00:05:11 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.