Server-side Request Forgery (SSRF) Affecting @theia/request package, versions <1.73.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-THEIAREQUEST-17810719
  • published3 Jul 2026
  • disclosed3 Jul 2026
  • creditZyy0530, 7thParkk, mauriceng98

Introduced: 3 Jul 2026

NewCVE-2026-10055  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @theia/request to version 1.73.0 or higher.

Overview

@theia/request is a Theia Proxy-Aware Request Service

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the request-service process. An attacker can access sensitive internal resources by sending crafted URLs to the backend, which then performs server-side HTTP requests and returns the responses. This can expose internal administrative endpoints, cloud instance metadata services, and other resources not intended to be accessible from the client. This is only exploitable if the service connection is reachable by untrusted users, such as in multi-tenant or publicly accessible deployments.

CVSS Base Scores

version 4.0
version 3.1