Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
odysseus-dev odysseus — Odysseus SSRF via Embedding Endpoint Configuration
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H N N N N 6.1 .0026 18.4 —
AFFECTED
Product Versions Fixed
odysseus unspecified —
TIMELINE
Aug 4 Reserved by VulnCheck
Aug 4 Published (CNA: VulnCheck)
Aug 5 EXPLOIT PUBLISHED — CVE-2026-70620 (odysseus-dev odysseus). Public exploit reference added.
Description
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range, or DNS rebind validation. Attackers can submit loopback addresses, RFC 1918 ranges, or link-local addresses through the embedding endpoint API to partially read responses from cloud instance metadata services, internal APIs, and other hosts reachable from the server.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 4, 2026 | Reserved | Reserved by VulnCheck |
| August 4, 2026 | Published | Published (CNA: VulnCheck) |
| August 5, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-70620 (odysseus-dev odysseus). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| odysseus-dev | odysseus | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-70620 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.