CVE-2026-21512

MEDIUM WAF: Medium
CVSS 6.5 Published: 2026-02-10
CWE-918

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

WAF Coverage Analysis

Server-Side Request Forgery (SSRF) Medium WAF Coverage

OWASP: A10:2021 SSRF

934xxx - Node.js / Generic Injection

Affected Software

VendorProductVersion
microsoftazure_devops_serverup to 2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0
microsoftazure_devops_server2022.2.0

References

Back to CVE Database