Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.0, <= 2026.1.11
- >= 2025.3.0, <= 2025.3.17
A server-side request forgery (SSRF) vulnerability has been identified in the gateway health check feature of Devolutions Server. This issue allows low-privileged authenticated users to send crafted API requests that could lead to unauthorized information disclosure. The vulnerability affects Devolutions Server versions 2026.1.1 through 2026.1.11 and 2025.3.1 through 2025.3.17.
Exploitation of this vulnerability could result in unauthorized access to sensitive information on the server.
Users are advised to upgrade to Devolutions Server version 2026.1.12 or higher or 2025.3.18 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.