Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution. | |
| Title | Kiteworks Core Server-Side Request Forgery through CRLF Injection | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:08:34.493Z
Reserved: 2026-09-28T17:39:13.564Z
Link: CVE-2026-102145
No data.
Status : Received
Published: 2026-09-30T21:17:03.390
Modified: 2026-09-30T21:17:03.390
Link: CVE-2026-102145
No data.
OpenCVE Enrichment
No data.
-
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')