CVE-2026-59101
Last modified
CVE-2026-59101 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during the initial setup window, causing the server to issue HTTP GET requests to internal or reserved addresses and leak information through echoed connection-error messages.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during the initial setup window, causing the server to issue HTTP GET requests to internal or reserved addresses and leak information through echoed connection-error messages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| EstrellaXD | Auto_Bangumi | < 3.2.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-59101?
How severe is CVE-2026-59101?
How do I fix CVE-2026-59101?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59096Dapr Sentry's OIDC discovery endpoint derives the issuer and…8.2
- CVE-2026-59097Taiga before 6.10.2 contains a missing authorization vulnera…6.9
- CVE-2026-59098LobeChat through 2.2.9 contains a broken access control vuln…7.1
- CVE-2026-59099Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic v…9.3
- CVE-2026-5910Integer overflow in Media in Google Chrome prior to 147.0.77…8.8
- CVE-2026-59100LobeChat through 2.2.9 contains a broken object level author…5
- CVE-2026-59102Forgejo before 15.0.3 contains a stored cross-site scripting…5.4
- CVE-2026-5911Policy bypass in ServiceWorkers in Google Chrome prior to 14…4.3
- CVE-2026-59112Improper verification of cryptographic signature and Imprope…4.4
- CVE-2026-59113Missing authorization in Visual Studio Code allows an unauth…8.8
- CVE-2026-59115'.../...//' in Microsoft Entra Provisioning Service (SyncFab…9.9
- CVE-2026-59117Integer overflow or wraparound in Windows Terminal allows an…7.5
Are you affected by CVE-2026-59101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
