Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Makeplane
Makeplane plane |
|
| Vendors & Products |
Makeplane
Makeplane plane |
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0. | |
| Title | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip (CGNAT/multicast) + DNS-rebinding TOCTOU | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T18:40:11.398Z
Reserved: 2026-10-02T18:16:13.629Z
Link: CVE-2026-104977
Updated: 2026-10-05T18:40:07.020Z
Status : Deferred
Published: 2026-10-05T18:17:33.080
Modified: 2026-10-05T19:17:15.790
Link: CVE-2026-104977
No data.
OpenCVE Enrichment
Updated: 2026-10-05T19:30:21Z