CVE-2026-65925: Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository
Published Jul 27, 2026
·Updated
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Affected Software
7 affected components
JFrog Artifactory Cargo remote repository
JFrog Artifactory<7.111.18
JFrog Artifactory>=7.117.0<7.117.25
JFrog Artifactory>=7.125.0<7.125.18
JFrog Artifactory>=7.133.0<7.133.27
JFrog Artifactory>=7.146.0<7.146.34
JFrog Artifactory>=7.161.0<7.161.15
Event History
Jul 27, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65925?
The severity of CVE-2026-65925 is medium, with a score of 6.5.
2
How do I fix CVE-2026-65925?
To fix CVE-2026-65925, restrict user permissions and carefully manage access to the JFrog Artifactory Cargo remote repository.
3
What type of vulnerability is CVE-2026-65925?
CVE-2026-65925 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
4
Who is affected by CVE-2026-65925?
Users with read access to the JFrog Artifactory Cargo remote repository could be affected by CVE-2026-65925.
5
What can an attacker do with CVE-2026-65925?
An attacker exploiting CVE-2026-65925 can make unintended requests to URLs via JFrog Artifactory and retrieve sensitive responses.