CVE-2026-24005 | openkruise up to 1.7.4/1.8.2 TCPSocket/HTTPGet server-side request forgery (GHSA-9fj4-3849-rv9g)
A vulnerability was found in openkruise kruise up to 1.7.4/1.8.2. It has been rated as critical. This issue affects some unknown processing of the component TCPSocket/HTTPGet. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-24005. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.