MEDIUM 5.5 GitHub
CVE-2025-24979
LF Edge eKuiper: SSRF in External Service
### Summary
Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints.
### Details
Prior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper manage
Affected Products
- go/github.com/lf-edge/ekuiper/v2 < 2.4.0
References
- https://github.com/advisories/GHSA-pqqc-8v73-9gg2
- https://github.com/lf-edge/ekuiper/security/advisories/GHSA-pqqc-8v73-9gg2
- https://github.com/lf-edge/ekuiper/releases/tag/v2.4.0
- https://github.com/advisories/GHSA-pqqc-8v73-9gg2
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-09 via GitHub. Affected: go/github.com/lf-edge/ekuiper/v2 < 2.4.0.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.