CVE-2026-53754
Last modified
CVE-2026-53754 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reach internal services and cloud metadata endpoints (e.g. 169.254.169.254) despite the filter by encoding an internal IPv4 address inside an IPv6 transition form, or by using the IPv6 unspecified address. Because the Docker API is unauthenticated by default (jwt_enabled: false), no credentials are required. This vulnerability is fixed in 0.8.8.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kidocode | Crawl4ai | < 0.8.8 |
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-4qqr-vv2q-cmr5Third Party Advisory, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-53754?
How severe is CVE-2026-53754?
How do I fix CVE-2026-53754?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53741Simple Link Directory through 9.0.4 interpolates the sld_no_…5.4
- CVE-2026-53742Simple Link Directory through 9.0.4 echoes embed shortcode a…5.4
- CVE-2026-5375An issue that could allow a user with access to a credential…2.7
- CVE-2026-53751DataEase is an open source data visualization and analysis t…8.7
- CVE-2026-53752docx4j is an open source Java library for creating, editing,…7.5
- CVE-2026-53753Crawl4AI is an open-source LLM friendly web crawler & scrape…10
- CVE-2026-53755Crawl4AI is an open-source LLM friendly web crawler & scrape…7.5
- CVE-2026-53756Emlog is an open source website building system. Prior to ve…4.9
- CVE-2026-53757Emlog is an open source website building system. In versions…6.9
- CVE-2026-53758Emlog is an open source website building system. In versions…8.7
- CVE-2026-53759linuxfabrik-lib provides Python modules for database access,…2
- CVE-2026-5376An issue that could prevent session inactivity timeouts from…5.9
Are you affected by CVE-2026-53754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
