Tenable Terrascan Server-Side Request Forgery Vulnerability in ARM and CloudFormation Template Processing

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in Tenable Terrascan versions through 1.18.3. This vulnerability arises when Terrascan is run in server mode, where it processes uploaded Infrastructure as Code (IaC) templates such as Azure Resource Manager (ARM) or AWS CloudFormation. During this parsing, Terrascan resolves external URLs referenced in the templates using the hashicorp/go-getter library, with all default detectors activated, including the FileDetector. An unauthenticated remote attacker can exploit this by uploading a template that includes a link to an attacker-controlled URL. Terrascan will then fetch this URL server-side, potentially leading to unauthorized access to internal resources or files. This issue is particularly concerning because it allows direct access to local files without the need for a specific redirect, which is usually required for file URLs.

Impact

Exploitation of this vulnerability allows for unauthorized server-side requests to be made, potentially leading to local file disclosure or access to internal services.

Added: May 19, 2026, 5:20 PM
Updated: May 19, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
8.8
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.