← Back to overview

Wyoming before version 1.10.2 contains a server-side request forgery (SSRF) vulnerability identified as CVE-2026-8712. Unauthenticated attackers with network access can exploit this flaw by supplying a malicious `uri` query parameter to the HTTP API. The vulnerability allows attackers to force outbound connections to arbitrary targets using `tcp://` or `unix://` URI schemes. Affected endpoints include /api/info, /api/speech-to-text, and /api/text-to-speech. Exploitation enables attackers to override the server-configured backend and redirect connections to attacker-chosen hosts. No authentication is required, making this accessible to any network-adjacent attacker. The issue has been patched in Wyoming version 1.10.2. Users are advised to upgrade immediately to mitigate the risk of internal network probing or service abuse.

Affected products

  • Wyoming

Related CVE's

  • CVE-2026-8712

Categories

  • Network Infrastructure
  • Web Technologies