{"ok":true,"trend":{"id":1115072,"platform":"mastodon","region":"global","key":"cve-2026-92931: progress software reports a server-side request forgery flaw in its sitefinity next.js sdk npm package.","title":"CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package.","url":"https://infosec.exchange/@suriq/117388549017322930","first_seen":"2026-10-05T13:33:11.919414Z","last_seen":"2026-10-05T13:33:11.919414Z","last_rank":8,"peak_rank":6,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.89109375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Progress Software has disclosed CVE-2026-92931, a server-side request forgery vulnerability in the Sitefinity Next.js SDK npm package. According to the advisory, a remote attacker could trick the server into making requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions reportedly begin with 15.1.8326, and developers using the package are being urged to review their installations.","why":"Security teams are discussing the newly published advisory so they can assess whether their applications use the affected package.","tone":"neutral","entities":["Progress Software","Sitefinity","Next.js SDK","npm","CVE-2026-92931"],"summarized_at":"2026-10-05T13:34:15.909971Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":633},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Progress Software discloses SSRF flaw in Sitefinity Next.js SDK","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-05T13:33:11.919414Z","rank":6,"volume":1},{"captured_at":"2026-10-05T13:33:11.919414Z","rank":8,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@suriq/117388549017322930","author":"suriq@infosec.exchange","title":null,"snippet":"CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package. A remote attacker could make server-side requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions run 15.1.8326…","posted_at":"2026-10-05T13:31:47Z","likes":1}],"elsewhere":[],"window":"7d"}}