CVE-2026-65924: Server-Side Request Forgery (SSRF) via Terraform Remote repository
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-65924?
CVE-2026-65924 is a vulnerability in JFrog Artifactory that allows for Server-Side Request Forgery (SSRF) through Terraform remote repositories.
What is the severity of CVE-2026-65924?
CVE-2026-65924 has a medium severity rating of 6.5.
How do I fix CVE-2026-65924?
To mitigate CVE-2026-65924, ensure that anonymous access to the repository is disabled and review the settings of Terraform remote repositories.
Who is affected by CVE-2026-65924?
Authenticated users, and potentially unauthenticated users if anonymous access is enabled, are affected by CVE-2026-65924.
What can an attacker do with CVE-2026-65924?
An attacker can exploit CVE-2026-65924 to make JFrog Artifactory issue outbound HTTP requests to arbitrary external resources.