CVE-2026-82477

medium

Description

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.

References

https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch

https://github.com/mitre/heimdall2/releases/tag/v2.14.0

https://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b485937b

Details

Source: Mitre, NVD

Published: 2026-08-29

Updated: 2026-08-29

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Severity: Medium