MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1. | |
| Title | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | |
| Weaknesses | CWE-367 CWE-918 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-26T20:22:41.423Z
Reserved: 2026-04-26T13:26:14.514Z
Link: CVE-2026-42336
No data.
Status : Received
Published: 2026-05-26T21:16:37.170
Modified: 2026-05-26T21:16:37.170
Link: CVE-2026-42336
No data.
OpenCVE Enrichment
Updated: 2026-05-26T21:30:16Z