CVE-2026-90486: openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery

Published Sep 12, 2026
·
Updated

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.

Affected Software

1 affected component
openstatusHQ/openstatus<=f04c827112f30a11d571ebdad3892826034d6265

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openstatusHQ openstatus to a version that resolves this vulnerability.

    Fixed in f04c827112f30a11d571ebdad3892826034d6265Patch 86f370c9c20074c3c3fdec53a359874b8e670fd4
  2. Compensating control

    Mitigate SSRF risk by restricting outbound server network access (e.g., firewall/egress allowlist) so openstatus cannot initiate requests to internal networks or arbitrary destinations.

Event History

Sep 12, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attack can be initiated remotely and requires no privileges, but it requires user interaction. The available data does not specify what form that interaction takes.

2

Which deployments should be considered affected?

openstatus deployments containing code up to commit f04c827112f30a11d571ebdad3892826034d6265 should be treated as affected. Because the project uses rolling releases, affected or fixed version numbers are not available.

3

How can this be remediated?

Apply the patch identified by commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. The issue was fixed through a silent patch.

4

How can I verify whether the fix is present?

Check whether the deployed source includes patch commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. Version-based verification is not possible from the available information because no fixed release versions are provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203