CVE-2026-30834: 
vulnerability analysis and mitigation

Overview

CVE-2026-30834 is a Server-Side Request Forgery (SSRF) vulnerability in PinchTab's /download endpoint that allows unauthenticated attackers to make arbitrary requests to internal network services and local system files, with full response exfiltration. It affects PinchTab versions up to and including 0.7.6 (Go module github.com/pinchtab/pinchtab/cmd/pinchtab). The vulnerability was published on March 5, 2026, by researcher aleister1102, reviewed by GitHub on March 6, 2026, and published to the NVD on March 7, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, PinchTab Advisory).

Technical details

The root cause is improper input validation (CWE-918) in the GET /download?url= handler located in internal/handlers/download.go. The user-supplied url parameter is passed directly to chromedp.Navigate(dlURL) — a headless Chrome browser instance — without any validation or sanitization, as shown in the vulnerable code at line 78: if err := chromedp.Run(ctx, chromedp.Navigate(dlURL)); err != nil. Because the request is executed by a headless Chrome process, it can access local files via the file:// scheme, internal services bound to localhost or private network IPs, and cloud provider metadata endpoints (e.g., 169.254.169.254). The server then returns the full captured response body to the requester, enabling complete data exfiltration with no authentication required (GitHub Advisory, PinchTab Advisory).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact. An unauthenticated attacker can read arbitrary local files (e.g., /etc/passwd, SSH keys, application secrets), probe and access internal network services not exposed externally, and retrieve cloud provider instance metadata including IAM credentials (e.g., AWS metadata at 169.254.169.254). In deployments where the PinchTab API is network-accessible, a compromised or malicious client can use this vulnerability as a pivot point to enumerate and attack internal infrastructure (GitHub Advisory, PinchTab Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly available in the official security advisory, making exploitation trivial. No authentication is required, and attack complexity is low. The EPSS score is approximately 0.032% (0.000320), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this vulnerability (detection ID 761789) (GitHub Advisory, PinchTab Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or locally accessible PinchTab instances running on the default port 9867, using network scanners or by checking for the PinchTab API endpoint. Confirm the version is 0.7.6 or earlier.
  2. Identify the vulnerable endpoint: Target the GET /download?url= endpoint, which accepts a user-controlled URL parameter without validation.
  3. Local file exfiltration: Send a crafted request using the file:// scheme to read sensitive local files:
    curl -X GET "http://<target>:9867/download?url=file:///etc/passwd"
  4. Internal service probing: Access internal services not reachable from the outside by specifying localhost or internal IP addresses:
    curl -X GET "http://<target>:9867/download?url=http://localhost:8080/internal-admin"
  5. Cloud metadata access: On cloud-hosted deployments, retrieve instance metadata and IAM credentials:
    curl -X GET "http://<target>:9867/download?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"
  6. Exfiltrate response: The PinchTab server returns the full response body of the targeted resource directly to the attacker, completing the data exfiltration (PinchTab Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the PinchTab server process to internal IP ranges, localhost services, or cloud metadata endpoints (e.g., 169.254.169.254); unusual HTTP GET requests to port 9867 with url= parameters containing file://, http://localhost, or internal RFC-1918 addresses.
  • Logs: PinchTab access logs showing repeated GET /download?url=file://... or GET /download?url=http://localhost:... requests; headless Chrome process logs indicating navigation to file:// or internal URLs.
  • Process: Unexpected child processes spawned by the PinchTab Go binary or headless Chrome instance accessing local file paths or making network connections to internal services.
  • File System: No direct file system artifacts from exploitation, but evidence of access to sensitive files (e.g., /etc/passwd, /etc/shadow, application config files) may be inferred from Chrome's access patterns in system audit logs (PinchTab Advisory).

Mitigation and workarounds

Upgrade PinchTab to version 0.7.7 or later, which patches the vulnerability by adding URL validation and sanitization to the /download handler. As an interim workaround, restrict network access to the PinchTab API (default port 9867) using firewall rules or network segmentation to prevent untrusted clients from reaching the endpoint. Avoid exposing the PinchTab API to untrusted networks even when authentication is enabled, as the vulnerability is exploitable by any authenticated user as well (GitHub Advisory, PinchTab Advisory).

Community reactions

The vulnerability was discussed on social media platforms including Mastodon and Bluesky shortly after disclosure. A technical write-up was published by Infinit Security at infinitsec.net covering the SSRF with full response exfiltration via the download handler. The Spanish national CERT (INCIBE-CERT) issued an early warning advisory for the vulnerability. OpenSUSE also published a security announcement referencing CVE-2026-30834 (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management