CVE-2026-15378

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Configurations

No configuration.

History

10 Jul 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 10:16

Updated : 2026-07-14 02:16


NVD link : CVE-2026-15378

Mitre link : CVE-2026-15378

CVE.ORG link : CVE-2026-15378


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)