[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-102105":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-30T20:14:14.158Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":24,"duplicate_of":9,"upstream":25,"downstream":26,"duplicates":27,"related":28,"reserved_at":9,"published_at":29,"modified_at":29,"state":30,"summary":31,"references_raw":38,"kevs":50,"epss":9,"epss_history":51,"metrics":52,"affected":60},"CVE-2026-102105","Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending on the services reachable from the gateway, this could disclose sensitive internal information or trigger unintended actions on internal systems.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-918","Server-Side Request Forgery (SSRF)","The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.","weakness","Incomplete","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-664","Server Side Request Forgery",[],[],[],[],[],[],[],"2026-09-30T20:25:02.880Z","Received",{"cisa_kev":32,"cisa_ransomware":32,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":33,"severity_score":34,"severity_version":35,"severity_source":36,"severity_vector":37,"severity_status":30},false,"critical",9.1,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",[39,45],{"url":40,"sources":41,"tags":43},"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-hq47-4whq-9hgv",[36,42],"nvd",[44],"Vendor Advisory",{"url":46,"sources":47,"tags":48},"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json",[36,42],[49],"Third Party Advisory",[],[],[53,58],{"source":36,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":54,"cvss_v4_0":9},{"baseScore":34,"baseSeverity":55,"vectorString":37,"impactScore":56,"exploitabilityScore":57},"CRITICAL",8.7,10,{"source":42,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":59,"cvss_v4_0":9},{"baseScore":34,"baseSeverity":55,"vectorString":37,"impactScore":56,"exploitabilityScore":57},[61],{"ecosystem":9,"name":62,"vendor":63,"product":64,"cpe_part":65,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":66},"Email Protection Gateway","kiteworks","email protection gateway","a",[67],{"version":68,"is_range":69,"range_type":36,"version_start":9,"version_start_type":9,"version_end":70,"version_end_type":71,"fixed_in":9},"\u003C 9.5.0",true,"9.5.0","excluding"]