{"ok":true,"trend":{"id":1129375,"platform":"mastodon","region":"global","key":"🔴 nextchat cve-2026-105238 — cvss 7.3 ssrf single unauthenticated request → server fetches any internal url or cloud met","title":"🔴 NextChat CVE-2026-105238 — CVSS 7.3 SSRF Single unauthenticated request → server fetches any internal URL or cloud met","url":"https://infosec.exchange/@threataft/117389138759379056","first_seen":"2026-10-05T16:17:32.122204Z","last_seen":"2026-10-05T16:17:32.122204Z","last_rank":11,"peak_rank":11,"last_volume":1,"peak_volume":1,"seen_count":1,"score":50.39,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A newly disclosed vulnerability, CVE-2026-105238, affects NextChat and carries a CVSS score of 7.3. Security researchers report a server-side request flaw that lets a single unauthenticated request make the server fetch arbitrary internal URLs or cloud metadata endpoints, bypassing access-code protection. No patched version has been confirmed; mitigations include blocking the x-base-url header at reverse proxies and restricting server egress.","why":"Security teams are sharing the flaw because it exposes NextChat deployments to cloud credential theft and there is no confirmed patch yet.","tone":"neutral","entities":["NextChat","CVE-2026-105238"],"summarized_at":"2026-10-05T16:19:17.716705Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":691},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"NextChat vulnerability allows unauthenticated SSRF attacks","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-05T16:17:32.122204Z","rank":11,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@threataft/117389138759379056","author":"threataft@infosec.exchange","title":null,"snippet":"🔴 NextChat CVE-2026-105238 — CVSS 7.3 SSRF Single unauthenticated request → server fetches any internal URL or cloud metadata endpoint (169.254.169.254). Access-code protection bypassed. No patched version confirmed. Fix: block x-base-url at reverse proxy + restrict egress. →…","posted_at":"2026-10-05T16:01:46Z","likes":1}],"elsewhere":[],"window":"7d"}}