CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-68927

CVE-2026-68927: Server-Side Request Forgery Port Restriction Bypass in Mobile Security Framework (MobSF)

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 18, 2026·7 min read·12 visits

Executive Summary (TL;DR)

MobSF prior to 4.5.1 validates the hostname of an Android App Link but appends the port afterward without validation, enabling SSRF and port scanning via crafted APK uploads.

A Server-Side Request Forgery (SSRF) vulnerability exists in Mobile Security Framework (MobSF) prior to version 4.5.1. The flaw occurs in the Android App Link validation process, where a split-validation vulnerability allows an authenticated attacker to perform port restriction bypasses and potential DNS rebinding attacks against internal infrastructure.

Vulnerability Overview

Mobile Security Framework (MobSF) is an automated, open-source mobile application security testing framework. It performs static and dynamic analysis on mobile application binaries, including Android APKs. During static analysis, MobSF parses the AndroidManifest.xml file to extract components, permissions, and deep link configurations. The vulnerability resides specifically within the Android App Link (Asset Links) verification engine.

The Asset Links mechanism allows Android applications to associate themselves with a web domain to handle URLs directly. MobSF attempts to verify these associations by checking for a valid Digital Asset Links JSON file at the standard path on the target host. Because this verification involves making outbound HTTP requests, it represents a significant attack surface if input validation is insufficient.

CVE-2026-68927 defines a server-side request forgery (SSRF) vulnerability where an authenticated attacker can bypass intended network restrictions. By uploading a specially crafted APK, the attacker can force the MobSF server to initiate outbound HTTP connections to non-standard ports or internal systems. This occurs because of a disconnect between how the application validates the target host and how it assembles the final destination URL.

Root Cause Analysis

The root cause of CVE-2026-68927 is a split-validation flaw (also known as a validation-vs-use discrepancy) within the App Link parsing logic. When parsing AndroidManifest.xml files, the function get_browsable_activities() in mobsf/StaticAnalyzer/views/android/manifest_analysis.py extracts the schema, host, and port configurations defined inside intent filters. These parameters are used to construct the target verification URL.

To prevent SSRF attacks against internal interfaces, the framework uses a security function named valid_host(). This function resolves the target host's DNS and inspects the resulting IP address. If the IP resides in a local, loopback, or private range (such as RFC 1918 space), the request is blocked. However, this safety check is only executed on the isolated hostname string without its associated port.

After valid_host() validates the bare hostname, the application performs a blind string concatenation. If an android:port attribute is specified in the manifest, MobSF appends this port to the validated hostname without subjecting the port to any validation. This allows the target URL to point to internal services or arbitrary restricted ports, bypassing the boundary checks enforced by the host validator.

Code Analysis

The vulnerability is located in mobsf/StaticAnalyzer/views/android/manifest_analysis.py. Below is the vulnerable code segment showing the blind concatenation of the port parameter after validation has occurred.

# Vulnerable Implementation
shost = f'{scheme}://{host}'
if port and is_number(port):
    # The port is appended to the URL without validating if it is a standard HTTP/HTTPS port
    c_url = f'{shost}:{port}{WELL_KNOWN_PATH}' 
else:
    c_url = f'{shost}{WELL_KNOWN_PATH}'

The patched implementation introduces validation in both get_browsable_activities() and _check_url() to reject non-standard ports. This implements a defense-in-depth model where the port is checked during URL construction and verified again before sending the HTTP request.

# Patched Implementation in get_browsable_activities()
shost = f'{scheme}://{host}'
if port and is_number(port):
    # Enforce that only standard web ports (80, 443) are allowed
    if int(port) not in (80, 443):
        logger.warning(
            'Non-standard port rejected in assetlinks '
            'check (port %s bypasses valid_host): %s',
            port, host)
        continue
    c_url = f'{shost}:{port}{WELL_KNOWN_PATH}'
else:
    c_url = f'{shost}{WELL_KNOWN_PATH}'
# Patched Implementation in _check_url()
purl = urlparse(url)
if (purl.path != WELL_KNOWN_PATH
    or len(purl.query) > 0
        or len(purl.params) > 0):
    logger.warning('Invalid Assetlinks URL: %s', url)
    continue
# Final check to verify that the parsed port is strictly safe
if purl.port and purl.port not in (80, 443):
    logger.warning(
        'Non-standard port in assetlinks URL rejected: %s', url)
    continue

Attack Methodology & DNS Rebinding

An attacker must first obtain authentication credentials to the target MobSF instance and possess privileges to upload files. The attacker then crafts a malicious Android application package (APK) with a custom AndroidManifest.xml payload. This manifest contains a browsable intent filter specifying a public domain name under the attacker's control along with a restricted target port, such as port 6379 (Redis) or port 22 (SSH).

If the attacker implements a DNS rebinding attack, they configure their domain name server with a low Time-To-Live (TTL) value of zero. When MobSF performs the initial DNS resolution during the valid_host() check, the domain name resolves to a legitimate public IP address (such as 8.8.8.8). The security validator approves the connection because the resolved IP is public and benign.

Immediately afterward, when the Python requests library resolves the domain name again to initiate the actual socket connection, the DNS server returns a private loopback or local IP address (such as 127.0.0.1). The connection is routed directly to the internal host on the specified non-standard port. By observing the difference in response times or connection states in the application logs, the attacker can conduct network scanning of internal assets.

Impact Assessment

The concrete security impact of this vulnerability is a partial compromise of confidentiality, resulting in internal service scanning and host detection. An attacker can determine whether specific ports are open or closed on the loopback interface of the MobSF server or within its local area network (LAN). This intelligence facilitates reconnaissance phase planning during multi-stage internal network penetration.

The severity of the exploit is constrained by multiple architectural factors. First, the HTTP GET request is made with the parameter allow_redirects=False inside _check_url(), which prevents the attacker from using HTTP redirects to pivot to other resources. Second, the path of the request is hardcoded to /.well-known/assetlinks.json, meaning the attacker cannot submit custom API calls or payloads to internal endpoints.

Because the request uses the GET method and cannot transmit arbitrary payloads, the integrity and availability of internal systems are not directly threatened. The CVSS score of 3.0 reflects these limitations. However, in environments where internal services trust requests originating from localhost or use HTTP GET parameters to trigger administrative actions, the threat profile may increase.

Remediation and Patch Assessment

To remediate CVE-2026-68927, administrators must upgrade all instances of Mobile Security Framework to version 4.5.1 or later. The patch effectively blocks arbitrary port specification by restricting the allowed ports in the asset links check to standard web ports (80 and 443). This prevents attackers from reaching high-risk internal administration interfaces like Redis, database servers, or shell endpoints.

While the applied patch successfully mitigates the port-abuse vector, it is important to note that DNS rebinding risks are not entirely eliminated. If the application environment allows outbound requests on ports 80 or 443 to resolve to internal services via DNS rebinding, those endpoints remain exposed. A complete mitigation would involve performing DNS resolution once, validating the IP address, and then routing the HTTP request directly to that validated IP while setting the original hostname in the HTTP Host header.

In scenarios where upgrading is delayed, administrators can deploy external controls to limit the risk. Configuring egress firewall rules to restrict outbound connections from the MobSF server to the internal network prevents the server from contacting other local systems. Additionally, monitoring container network traffic for unauthorized outgoing HTTP requests can help detect exploitation attempts.

Fix Analysis (1)

Technical Appendix

CVSS Score
3.0/ 10
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Affected Systems

Mobile Security Framework (MobSF)

Affected Versions Detail

Product
Affected Versions
Fixed Version
Mobile-Security-Framework-MobSF
MobSF
< 4.5.14.5.1
AttributeDetail
CWE IDCWE-918
Attack VectorNetwork (AV:N)
CVSS Score3.0 (Low)
EPSS ScoreN/A
ImpactLow Confidentiality
Exploit StatusProof-of-Concept / Conceptual
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

The web application receives a URL or similar request parameter from an untrusted source and attempts to read or send data to that destination without sufficient validation.

Vulnerability Timeline

Vulnerability identified and fixed in hotfix commit 62563ca429a75b3e5d47a13b958e1d2e7d5e2bbf
2026-07-05
Official NVD CVSS scoring and details published for CVE-2026-68927
2026-08-18
GitHub Security Advisory GHSA-95px-34x5-p37h publicly released
2026-08-18
Safe version 4.5.1 released to the public
2026-08-18

References & Sources

  • [1]Official GitHub Advisory
  • [2]Official Fix Commit
  • [3]Fix Pull Request
  • [4]MobSF v4.5.1 Release Page
  • [5]CVE.org Authority Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-105849
7.7

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-86540
8.5

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 3 hours ago•CVE-2026-105854
8.7

CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS

Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105855
7.6

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-105804
5.7

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•GHSA-WQ5F-XC86-PV6W
7.8

CVE-2026-96889: Remote Code Execution via Use-After-Free in librsvg (VectorFreed)

VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.

Amit Schendel
Amit Schendel
6 views•8 min read