CVE-2026-65318: Server-Side Request Forgery (SSRF) in Weaviate Verba
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials.
AI Analysis
Technical Summary
CVE-2026-65318 is an unauthenticated SSRF vulnerability in Weaviate Verba version 2.1.3. The vulnerability exists because the /ws/import_files WebSocket endpoint accepts attacker-controlled URLs in the HTMLReader configuration without authentication or proper validation. This allows remote attackers to cause the backend server to make arbitrary HTTP GET requests, including to internal services that may expose sensitive credentials or data. The CVSS 4.0 base score is 9.2, reflecting high impact and ease of exploitation without privileges or user interaction.
Potential Impact
Successful exploitation allows unauthenticated attackers to make the backend server perform arbitrary HTTP GET requests, potentially accessing internal resources such as co-located database endpoints or cloud instance metadata services. This can lead to disclosure of sensitive credentials and internal information, posing a critical security risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the /ws/import_files WebSocket endpoint to trusted users or networks, and monitor for suspicious requests targeting this endpoint. Avoid exposing this endpoint publicly if possible.
CVE-2026-65318: Server-Side Request Forgery (SSRF) in Weaviate Verba
Description
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials.
CVSS v4.0
Score 9.2critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65318 is an unauthenticated SSRF vulnerability in Weaviate Verba version 2.1.3. The vulnerability exists because the /ws/import_files WebSocket endpoint accepts attacker-controlled URLs in the HTMLReader configuration without authentication or proper validation. This allows remote attackers to cause the backend server to make arbitrary HTTP GET requests, including to internal services that may expose sensitive credentials or data. The CVSS 4.0 base score is 9.2, reflecting high impact and ease of exploitation without privileges or user interaction.
Potential Impact
Successful exploitation allows unauthenticated attackers to make the backend server perform arbitrary HTTP GET requests, potentially accessing internal resources such as co-located database endpoints or cloud instance metadata services. This can lead to disclosure of sensitive credentials and internal information, posing a critical security risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the /ws/import_files WebSocket endpoint to trusted users or networks, and monitor for suspicious requests targeting this endpoint. Avoid exposing this endpoint publicly if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-21T20:57:44.880Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fee4e9c2644c7f8d5ec3d
Added to database: 07/21/2026, 22:10:22 UTC
Last enriched: 07/21/2026, 22:21:56 UTC
Last updated: 07/22/2026, 00:10:25 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.