MikeTrendsTrends right now

search

NextChat

Trends

  1. 1
    NextChat vulnerability allows unauthenticated SSRF attacks●🔴 NextChat CVE-2026-105238 — CVSS 7.3 SSRF Single unauthenticated request → server fetches any internal URL or cloud metMmastodonTechnologyCybersecurity11 d ago

    A newly disclosed vulnerability, CVE-2026-105238, affects NextChat and carries a CVSS score of 7.3. Security researchers report a server-side request flaw that lets a single unauthenticated request make the server fetch arbitrary internal URLs or cloud metadata endpoints, bypassing access-code protection. No patched version has been confirmed; mitigations include blocking the x-base-url header at reverse proxies and restricting server egress.