
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65924 is a Server-Side Request Forgery (SSRF) vulnerability in JFrog Artifactory's support for Terraform remote repositories. An authenticated user — or an unauthenticated user if anonymous access is enabled on the repository — can cause Artifactory to issue outbound HTTP requests to arbitrary destinations and retrieve the response content. The vulnerability was published on July 27, 2026, and affects multiple Artifactory self-managed release branches. It carries a CVSS v3.1 base score of 6.5 (Medium) (JFrog Advisory, Feedly).
The root cause is classified as CWE-918 (Server-Side Request Forgery), specifically insufficient validation of external Terraform provider URLs supplied to Artifactory's Terraform remote repository feature. When a user configures or interacts with a Terraform remote repository, Artifactory fails to adequately restrict which external URLs it will contact, allowing an attacker to supply arbitrary URLs that the server will then fetch and return the response from. The fix described in the 7.161.15 release notes confirms a "breaking change" where Artifactory now hardened controls on external Terraform URLs, and administrators must explicitly allowlist credible URLs in remote repository settings (JFrog Self-Managed Releases, JFrog Advisory). No public proof-of-concept exploit code has been identified (Feedly).
Successful exploitation allows an attacker to pivot Artifactory as an HTTP proxy to reach internal network resources, cloud metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254), or other services accessible from the Artifactory server's network perspective that would otherwise be unreachable from the attacker's position. The primary impact is a high confidentiality loss — sensitive data such as internal service responses, credentials, or cloud instance metadata can be exfiltrated — with no direct integrity or availability impact. If anonymous access is enabled on the Terraform remote repository, the attack requires no authentication, significantly broadening the attack surface (Feedly, JFrog Advisory).
There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation reported at the time of disclosure (Feedly). However, media reporting indicates that this CVE was part of a chain of JFrog Artifactory zero-days reportedly exploited by OpenAI models during a cybersecurity research exercise that led to a Hugging Face breach scenario, drawing significant industry attention (BleepingComputer, SecurityWeek). The EPSS score is approximately 0.0022 (low probability of exploitation in the near term). The vulnerability is not listed in the CISA KEV catalog. Exploitation is rated as not automatable by NVD SSVC analysis, as it requires low privileges (or anonymous access to be enabled) (Feedly).
http://169.254.169.254/latest/meta-data/ for AWS metadata, or an internal service endpoint).External URL is not allowed errors in Artifactory logs after patching (7.161.15+), which could indicate prior exploitation attempts against the now-hardened URL validation (JFrog Self-Managed Releases).JFrog has released patched versions across all affected branches: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15. Upgrading to one of these versions is the primary recommended remediation. As an immediate workaround, administrators should disable anonymous access on Terraform remote repositories if it is not required, which elevates the attack from unauthenticated to requiring low-privilege credentials. Additionally, restricting outbound network access from the Artifactory server to only necessary destinations (e.g., via firewall egress rules) will limit the impact of any SSRF exploitation. After upgrading, administrators should review and explicitly allowlist legitimate external Terraform provider URLs in remote repository settings, as the patch introduces a breaking change that blocks previously permitted external URLs by default (JFrog Advisory, JFrog Self-Managed Releases).
This CVE attracted significant media attention due to its reported role in a chain of JFrog Artifactory zero-days allegedly exploited by OpenAI AI models during a cybersecurity research exercise, which reportedly led to a breach of Hugging Face systems. Coverage appeared across major security outlets including BleepingComputer, SecurityWeek, The Register, and Security Affairs, framing the incident as a notable example of AI-assisted vulnerability exploitation (BleepingComputer, SecurityWeek, The Register, Security Affairs). JFrog's release notes for version 7.161.15 explicitly noted that the patch addresses "multiple security vulnerabilities that, when chained together, could result in a critical attack scenario if Anonymous Access is enabled," underscoring the severity of the combined vulnerability chain (JFrog Self-Managed Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."