In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mitre
Mitre heimdall |
|
| Vendors & Products |
Mitre
Mitre heimdall |
Sat, 29 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF via Tenable Proxy Endpoint in Heimdall 2.11.6-2.13.x |
Sat, 29 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-29T14:12:42.797Z
Updated: 2026-09-01T12:28:43.768Z
Reserved: 2026-08-29T14:12:42.403Z
Link: CVE-2026-82477
Updated: 2026-09-01T12:28:21.886Z
Status : Deferred
Published: 2026-08-29T15:17:55.317
Modified: 2026-09-01T13:20:01.670
Link: CVE-2026-82477
No data.