Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/tenable/terrascan |
|
Wed, 20 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tenable:terrascan:*:*:*:*:*:*:*:* |
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable terrascan |
|
| Vendors & Products |
Tenable
Tenable terrascan |
Tue, 19 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF in Tenable Terrascan Remote Scan Enables Local File Read and Credential Disclosure |
Tue, 19 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response header, allowing the attacker's server to redirect the download to a file:// URL, enabling local file read. Additionally, HttpGetter has Netrc set to true, causing it to read ~/.netrc and send stored credentials to attacker-controlled hostnames. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. | |
| Weaknesses | CWE-610 CWE-73 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-05-19T17:09:32.072Z
Reserved: 2026-05-19T13:49:09.883Z
Link: CVE-2026-47357
Updated: 2026-05-19T17:09:26.177Z
Status : Analyzed
Published: 2026-05-19T17:16:22.863
Modified: 2026-06-17T10:54:33.520
Link: CVE-2026-47357
No data.
OpenCVE Enrichment
Updated: 2026-05-20T10:39:13Z