CVE-2026-5538

A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

24 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue detectada en QingdaoU OnlineJudge hasta la versión 1.6.1. Afectada por este problema es la función service_url del archivo JudgeServer.service_url del componente Endpoint judge_server_heartbeat. La manipulación resulta en falsificación de petición del lado del servidor. Es posible lanzar el ataque remotamente. El proveedor fue contactado con antelación sobre esta divulgación, pero no respondió de ninguna manera.

05 Apr 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-05 04:16

Updated : 2026-07-24 20:10


NVD link : CVE-2026-5538

Mitre link : CVE-2026-5538

CVE.ORG link : CVE-2026-5538


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)