CVE-2026-70548: SSRF In CocoaPods Via JFrog Artifactory External Dependency
Published Aug 25, 2026
·Updated
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
Affected Software
2 affected components
CocoaPods
JFrog Artifactory
Event History
Aug 25, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires low-level privileges. No user interaction is required.
2
Which environments should be prioritized for review?
Prioritize JFrog Artifactory deployments using External Dependency with access to remote CocoaPods repositories. The issue is described as occurring only under specific circumstances.
3
What is the reported impact if exploitation succeeds?
The reported impact is limited to low availability impact. No confidentiality or integrity impact is listed.