CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-55455

Critical · CVSS 9.1

Appsmith — Server-Side Request Forgery (SSRF) via HTTP host filter bypass

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-918

Description

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local, link-local, fc00::/7) exists only on a separate code path used by SMTP, not by the HTTP plugin path. As a result, an authenticated user can craft outbound requests that reach loopback-bound services inside the container. This vulnerability is fixed in 2.1.

Search profile — drives PoC discovery

Symbols WebClientUtilsREST API pluginGraphQL datasource pluginoutbound HTTP host filterdenylistloopbackany-locallink-localfc00::/7SMTPHTTP plugin path
Keywords CVE-2026-55455Appsmith SSRFAppsmith WebClientUtils bypassAppsmith HTTP host filter bypassAppsmith loopback SSRFGHSA-m23h-pvf3-2m7pAppsmith REST API SSRFAppsmith GraphQL SSRFAppsmith denylist bypassAppsmith internal service SSRF
Versions: < 2.1

References

Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-07-01T18:30:14.000Z