GHSA-hx93-cpfv-g2pwMediumCVSS 8.3

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows...

Published
September 1, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious uri query parameter to the HTTP API. Attackers can pass arbitrary tcp:// or unix:// URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts.

🔗 References (4)