CVE-2026-65057

CRITICAL

Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck

Title source: cna
STIX 2.1

Description

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network reconnaissance.

References (3)

Core 3

Scores

CVSS v3 9.3
EPSS 0.0025
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
keephq/keep < 91c75e0
Published Jul 21, 2026
Tracked Since Jul 22, 2026