CVE-2026-55372 is a pre-authentication server-side request forgery vulnerability in NukeViet. The issue arises from insufficient validation of client-supplied forwarded headers, specifically X-Forwarded-Host and X-Forwarded-Proto, which are consumed by server_info_update() when constructing an outbound cURL request. Because these values are not properly normalized and constrained before use, an unauthenticated attacker can influence the destination of a server-initiated request. The vulnerable behavior permits blind SSRF against attacker-selected internal or external targets. Available details indicate the request behavior is constrained by a fixed request path, use of the HEAD method, and absence of reflected response content, which limits exploitability beyond network reachability and limited side effects such as cached header poisoning.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.