Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #6
Progress Software discloses SSRF flaw in Sitefinity Next.js SDK
Original: CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package.
Progress Software has disclosed CVE-2026-92931, a server-side request forgery vulnerability in the Sitefinity Next.js SDK npm package. According to the advisory, a remote attacker could trick the server into making requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions reportedly begin with 15.1.8326, and developers using the package are being urged to review their installations.
Why now: Security teams are discussing the newly published advisory so they can assess whether their applications use the affected package.
Progress SoftwareSitefinityNext.js SDKnpmCVE-2026-92931
Rank over time, top of the chart is #1. 2 snapshots from 5 h ago to 5 h ago.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1115072