CVE-2026-100893 | Privoce VoceChat Server up to 0.5.36 open_graphic_parse Endpoint src/api/resource.rs open_graph::fetch url server-side request forgery

SecurityVulns

A vulnerability described as critical has been identified in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery.

This vulnerability is tracked as CVE-2026-100893. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More