CVE-2026-54885 | malach-it boruta up to 2.3.6 HTTP Client clients.ex request_uri/jwks_uri server-side request forgery

SecurityVulns

A vulnerability was found in malach-it boruta up to 2.3.6. It has been classified as critical. This affects the function Boruta.Oauth.Request.Base.fetch_unsigned_request/1/Boruta.Openid.parse_registration_params/2/Boruta.Ecto.Clients.refresh_jwk_from_jwks_uri/1 of the file lib/boruta/oauth/request/base.ex/lib/boruta/openid.ex/lib/boruta/adapters/ecto/clients.ex of the component HTTP Client. Performing a manipulation of the argument request_uri/jwks_uri results in server-side request forgery.

This vulnerability is reported as CVE-2026-54885. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More