Skip to content
JFrogCVE-2026-65924

JFrog artifactory: server-side request forgery

Medium6.5CVE-2026-65924 · Published Jul 27, 2026 · updated Jul 30, 2026

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
< 7.111.187.111.18
>= 7.117.0, < 7.117.257.117.25
>= 7.125.0, < 7.125.187.125.18
>= 7.133.0, < 7.133.277.133.27
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: information disclosure
Medium6.5Jul 27
JFrog artifactory: server-side request forgery
Medium6.5Jul 27
JFrog artifactory: path traversal
High8.8Jul 27
JFrog artifactory: missing authorization
High7.1Jul 27
JFrog artifactory: server-side request forgery
Medium6.8Jul 27
JFrog artifactory: server-side request forgery
Medium6.5Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.