criticalCVSS 9.4Vulnerability

GHSA-68r5-9hpg-7qw9

The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-side without a scheme allowlist, egress filtering, or a size cap, and is reachable without authentication by default. A remote unauthenticated attacker can submit a DSML add/modify request whose value is a URI to (1) perform server-side request forgery against internal services and the cloud metadata endpoint (SSRF), (2) read local files via file: URIs, and (3) exhaust memory through an unbounded response read (DoS). Fixed in 5.1.2: anyURI dereferencing is disabled by default; when enabled it is limited to an http/https allowlist, rejects loopback/link-local/private/reserved targets, refuses HTTP redirects, and caps the bytes read. The gateway also now requires container-managed authentication by default.

Properties

ghsa_id
GHSA-68r5-9hpg-7qw9
severity
critical
summary
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
cvss_score
9.4
cve_id
GHSA-68r5-9hpg-7qw9
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
is_ghsa_only
true
ghsa_published
2026-07-24T21:46:06Z
source_url
https://github.com/advisories/GHSA-68r5-9hpg-7qw9
ghsa_updated
2026-07-24T21:46:08Z

Related Entities (6)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/org.openidentityplatform.opendj:opendj-dsml-servlet

AFFECTS (1)

[Software]maven/org.openidentityplatform.opendj:opendj-dsml-servlet

HAS_WEAKNESS (3)

[Weakness]External Control of File Name or Path
[Weakness]Server-Side Request Forgery (SSRF)
[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph