CVE-2026-56261
Severity CVSS v4.0:
CRITICAL
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
10/07/2026
Last modified:
13/07/2026
Description
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.60
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* | 0.8.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page


