CVE-2026-90486: openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery
A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openstatusHQ openstatusto a version that resolves this vulnerability.Fixed in f04c827112f30a11d571ebdad3892826034d6265Patch 86f370c9c20074c3c3fdec53a359874b8e670fd4 - Compensating control
Mitigate SSRF risk by restricting outbound server network access (e.g., firewall/egress allowlist) so openstatus cannot initiate requests to internal networks or arbitrary destinations.
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges, but it requires user interaction. The available data does not specify what form that interaction takes.
Which deployments should be considered affected?
openstatus deployments containing code up to commit f04c827112f30a11d571ebdad3892826034d6265 should be treated as affected. Because the project uses rolling releases, affected or fixed version numbers are not available.
How can this be remediated?
Apply the patch identified by commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. The issue was fixed through a silent patch.
How can I verify whether the fix is present?
Check whether the deployed source includes patch commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. Version-based verification is not possible from the available information because no fixed release versions are provided.