A high-severity flaw tracked as CVE-2026-43910 affects Appium Java Client versions 8.2.1 through before 10.1.1, allowing server-side request forgery and network pivoting when directConnect(true) is enabled. The issue stems from AppiumCommandExecutor.setDirectConnect() rebuilding the client server URL from untrusted NEW_SESSION response fields while only verifying that the protocol is HTTPS, which means a rogue or compromised Appium server can redirect subsequent session traffic to attacker-chosen destinations.
The vulnerability could let attackers intercept session traffic and reach internal network resources, including potential access to cloud metadata services such as IMDS for credential theft. Appium addressed the issue in version 10.1.1 through additional security checks on the overrideServerUrl API, including validation logic designed to block unsafe direct-connect targets such as 0.0.0.0, [::], and multicast addresses; organizations are advised to upgrade to 10.1.1 or disable directConnect if they cannot update immediately.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-43910 was published as a high-severity vulnerability affecting Appium Java Client versions 8.2.1 through before 10.1.1. The flaw allows network pivoting and SSRF via unvalidated directConnect redirect handling in AppiumCommandExecutor when directConnect(true) is enabled.
Appium released Java Client version 10.1.1, whose release notes say it performs additional security checks on the overrideServerUrl API. This version is identified as the fix for the affected directConnect URL handling issue.
A security-related pull request was merged into the Appium Java Client, adding DirectConnectUrlSafety validation around overrideServerUrl and tests covering disallowed addresses such as 0.0.0.0, [::], and 224.0.0.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.