CVE-2026-59085: Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.
This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStack webhook moduleto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStack webhook moduleto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Frequently Asked Questions
Which CloudStack deployments need remediation?
Deployments running versions 4.20.0.0 through 4.20.3.0, or 4.21.0.0 through 4.22.1.0, are affected. Upgrade to 4.20.3.1 or 4.22.1.1 or a later version.
What feature is involved in exploitation?
The issue is exploitable through webhook delivery requests in the CloudStack webhook module. Environments using this module should prioritize the specified upgrade.