CVE-2026-91079: Huly Platform through 0.7.426 SSRF via Print Service

Published Sep 14, 2026
·
Updated

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

Affected Software

1 affected component
Huly Platform<=0.7.426

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Huly Platform to a version that resolves this vulnerability.

    Fixed in 0.7.426

Event History

Sep 14, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:20 PM
DescriptionSeverityWeakness
Mar 24, 58674
Event
via NVD·10:09 AM

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Huly workspace member can exploit it. The exposed functionality is the print endpoint, which accepts URLs for Puppeteer to render.

2

What can an attacker reach through the vulnerable endpoint?

An attacker can provide arbitrary URLs and cause the server-side print service to request them. This can enable access to internal network hosts and metadata services, with the rendered result returned as a downloadable PDF or image.

3

Are unauthenticated internet users able to exploit this directly?

The available information identifies authenticated workspace membership as the required privilege. It does not indicate that unauthenticated users can invoke the vulnerable print endpoint.

4

What configuration condition causes the issue?

The print service lacks hostname allowlist validation for URLs submitted to the print endpoint. The provided data does not describe a configuration-based mitigation or workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203