CVE-2026-92789: Server-Side Request Forgery (SSRF) in Graylog2 graylog2-server
Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services, enabling the server to fetch and return internal responses.
AI Analysis
Technical Summary
Graylog2 graylog2-server versions up to 7.1.4 implement an allowlist check for outbound URLs before making requests. However, the validation is bypassed after HTTP redirects because the server does not re-validate the redirected URLs. Attackers with certain permissions (lookup table or event notification) can exploit this by creating allowlisted endpoints that redirect to internal network services. This results in the server fetching and returning responses from internal services, effectively enabling SSRF.
Potential Impact
An attacker with lookup table or event notification permissions can exploit this vulnerability to make the Graylog server perform unauthorized requests to internal services. This can lead to information disclosure from internal network resources that are otherwise inaccessible externally. The vulnerability has a CVSS 4.0 base score of 7.1 (high severity), indicating significant risk but requiring some level of privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict permissions to lookup table and event notification features to trusted users only. Monitor for unusual outbound requests and consider network-level controls to limit server access to internal services.
CVE-2026-92789: Server-Side Request Forgery (SSRF) in Graylog2 graylog2-server
Description
Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services, enabling the server to fetch and return internal responses.
CVSS v4.0
Score 7.1high
Affected software
Graylog2
graylog2-server
pkg:github/graylog2/graylog2-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Graylog2 graylog2-server versions up to 7.1.4 implement an allowlist check for outbound URLs before making requests. However, the validation is bypassed after HTTP redirects because the server does not re-validate the redirected URLs. Attackers with certain permissions (lookup table or event notification) can exploit this by creating allowlisted endpoints that redirect to internal network services. This results in the server fetching and returning responses from internal services, effectively enabling SSRF.
Potential Impact
An attacker with lookup table or event notification permissions can exploit this vulnerability to make the Graylog server perform unauthorized requests to internal services. This can lead to information disclosure from internal network resources that are otherwise inaccessible externally. The vulnerability has a CVSS 4.0 base score of 7.1 (high severity), indicating significant risk but requiring some level of privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict permissions to lookup table and event notification features to trusted users only. Monitor for unusual outbound requests and consider network-level controls to limit server access to internal services.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-16T19:31:53.122Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aab006355bf5e2cf5231fcc
Added to database: 09/16/2026, 20:47:31 UTC
Last enriched: 09/16/2026, 21:48:19 UTC
Last updated: 09/17/2026, 02:02:53 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.