SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82638

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in Jina AI Reader allows unauthenticated attackers to exploit server-side request forgery by disabling the private-address guard in non-Google Cloud environments. This flaw enables attackers to access sensitive cloud metadata and internal service content by supplying publicly resolvable hostnames that map to private addresses. Organizations using Jina AI Reader outside of Google Cloud should prioritize addressing this issue to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82638
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.