CVE-2026-57573
Last modified
CVE-2026-57573 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with crawler_config.stream=true with a URL pointing at an internal, private, or link-local address; the server fetched it and streamed the response body back. This issue is fixed in version 0.9.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kidocode | Crawl4ai | < 0.9.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57573?
How severe is CVE-2026-57573?
How do I fix CVE-2026-57573?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5754Reflected Cross-Site Scripting (XSS) Vulnerability in Radwar…6.1
- CVE-2026-5755Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5…6.5
- CVE-2026-5756Unauthenticated Configuration File Modification Vulnerabilit…7.5
- CVE-2026-5757Unauthenticated remote information disclosure vulnerability …7.5
- CVE-2026-57571Crawl4AI is an open-source LLM-friendly web crawler and scra…9.6
- CVE-2026-57572Crawl4AI is an open-source LLM-friendly web crawler and scra…10
- CVE-2026-57574Misskey is an open source, federated social media platform. …7.4
- CVE-2026-57575Misskey is an open source, federated social media platform. …6.9
- CVE-2026-5758JavaScript is vulnerable to prototype pollution in Mafintosh…6.5
- CVE-2026-57584Phalcon is a high-performance, full-stack PHP framework. Pri…8.7
- CVE-2026-57585MessagePack is the serializer implementation for Python msgp…7.5
- CVE-2026-57587A SQL injection vulnerability in Nessus allows a remote, una…5.3
Are you affected by CVE-2026-57573?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
