Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kyegomez
Kyegomez swarms |
|
| Vendors & Products |
Kyegomez
Kyegomez swarms |
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials. | |
| Title | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-30T17:36:54.646Z
Reserved: 2026-07-29T13:09:45.993Z
Link: CVE-2026-67346
Updated: 2026-07-30T17:29:35.667Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:26:32Z
-
CWE-918
Server-Side Request Forgery (SSRF)