Back Redpacketsecurity CVE Alert: CVE-2026-100893 – Privoce
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early this disclosure but did not respond in any way.
**Risk verdict:** Treat this as a high-priority exposure review: the weakness is remotely reachable without authentication or user action, and exploit material is public, although KEV, SSVC and EPSS status are not provided.
**Why this matters:** A successful request may make the server connect to attacker-chosen destinations, exposing internal services or cloud metadata and potentially enabling follow-on access. The assessed impact is limited, but the server’s network position can make otherwise inaccessible systems reachable.
**Most likely attack path:** An attacker submits a crafted URL to the affected fetch functionality over the network; low complexity and no privileges or victim interaction are required. Scope is assessed as unchanged, but SSRF can still provide a pivot into services reachable from the host.
**Who is most exposed:** Internet-facing deployments are at greatest risk, particularly self-hosted chat servers with broad outbound access or cloud-hosted instances with accessible metadata services.
Alert on server-originated requests to loopback, private, link-local or metadata addresses.
Review DNS and proxy logs for unusual destinations or ports contacted by the chat service.
Inspect application logs for submitted URLs targeting internal address ranges.
Check for unexpected outbound connections from the server process.
Mitigation and prioritisation:
Identify exposed deployments and confirm a vendor-fixed release; no fix details are supplied here.
Until patched, restrict outbound traffic to required destinations and block private, loopback and metadata ranges.
Limit external access to the service where operationally feasible.
Test changes in staging, then deploy promptly; monitor egress during and after rollout.
Obtain KEV, SSVC and EPSS status before final priority assignment; current exploitation status remains uncertain.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
