What is CVE-2026-19000?
A server-side request forgery (SSRF) vulnerability was found in JeecgBoot up to version 3.9.2, specifically in the Anonymous Chat Attachment Parser within the `/airag/chat/send` file. This allows remote attackers to send unauthorized requests from the server. Users should immediately update JeecgBoot to the latest version and apply security patches.
Azərbaycanca: JeecgBoot-un 3.9.2 versiyasına qədər olan versiyalarında `/airag/chat/send` faylındakı Anonymous Chat Attachment Parser komponentində server-side request forgery (SSRF) zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə server adından icazəsiz sorğular göndərməyə imkan verir. İstifadəçilər dərhal JeecgBoot-u ən son versiyaya yeniləməli və təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of JeecgBoot are affected by the CVE-2026-19000 SSRF vulnerability?
JeecgBoot versions up to 3.9.2 are affected by this vulnerability.
In which component of JeecgBoot does the CVE-2026-19000 vulnerability exist?
The vulnerability exists in the Anonymous Chat Attachment Parser component within the `/airag/chat/send` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.