CVE-2025-58441 MEDIUM

CVE-2025-58441: Knowage is vulnerable to blind server-side request forgery (SSRF)

Vendor Knowagelabs
Product Knowage-Server
Weakness CWE-918 · SSRF
Published January 7, 2026
Last update January 7, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.

Key dates

02Disclosure timeline

January 7, 2026 CVE published
January 7, 2026 Record updated

Related vulnerabilities

04Related CVE