CVE-2026-24902 | TrustTunnel up to 0.9.113 TcpStream::connect server-side request forgery (GHSA-hgr9-frvw-5r76 / EUVD-2026-4951)
A vulnerability classified as critical was found in TrustTunnel up to 0.9.113. This impacts the function TcpStream::connect. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-24902. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.