CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-65057 — Keep (commit 91c75e0) contains a server-side request forgery vulnerability that ...

·Source: NIST NVD

Updated:

Executive Summary

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud

Analysis

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network reconnaissance. CVSS Score: 9.3. Published: 2026-07-21T21:16:54.427.

Indicators of Compromise (1)

CVE (1)
CVE-2026-65057
Source Attribution

Originally published by NIST NVD on Jul 21, 2026. Verified by: NIST.

Related Threats

LOWVulnerabilityNEW

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a

Krebs on Security
MEDIUMVulnerability

Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack

Milford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email alerts, shared with DataBreaches by a town resident, reveal... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-60210 — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo...

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

CVE-2026-60210
NIST NVD