← Back to overview

Bisheng versions through 2.6.0-fix2 contain a server-side request forgery (SSRF) vulnerability in the POST /api/v1/workflow/report/callback endpoint. The endpoint lacks authentication and imposes no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to probe and enumerate internal network services and cloud metadata endpoints. Captured responses can be retrieved from object storage using caller-supplied object names, amplifying the data exposure risk. The vulnerability enables attackers to pivot into internal infrastructure without any credentials. Cloud environments are particularly at risk due to metadata endpoint exposure. No patches beyond the affected 2.6.0-fix2 release are indicated in the advisory. The issue is tracked as CVE-2026-82285 and has been reported via GitHub issues and VulnCheck advisories.

Affected products

  • bisheng 2.6.0-fix2

Related CVE's

  • CVE-2026-82285

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Web Technologies