ProjectDiscovery's nuclei-templates repository received pull requests adding detection coverage for two server-side request forgery issues: CVE-2026-27826, described as an MCP Atlassian SSRF reachable via HTTP headers, and CVE-2025-62718, an Axios SSRF vulnerability tied to a hostname normalization and NO_PROXY bypass. The updates indicate that public detection content is being prepared for defenders to identify exposed systems affected by both flaws.
The GitHub activity shows the templates were submitted through separate bounty-related pull requests and routed through the project's normal review workflow, including automated assignment and reviewer requests. While the referenced discussions expose few technical specifics beyond the vulnerability names and high-level attack paths, the additions signal active security community attention on SSRF risks affecting both Atlassian-related MCP deployments and applications using vulnerable Axios proxy-handling logic.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request was published in the projectdiscovery/nuclei-templates repository to add a template for CVE-2025-62718, an Axios SSRF issue involving a hostname normalization bypass and NO_PROXY bypass behavior. The available content shows repository workflow and review-request activity but few additional technical details.
A GitHub pull request was published in the projectdiscovery/nuclei-templates repository to add detection coverage for CVE-2026-27826, described as an MCP Atlassian SSRF via HTTP headers issue. The visible activity includes commit b249bec and automated review workflow actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.