CVE-2020-13226: WSO2 API Manager

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

Affected products

  • WSO2 API Manager: version 3.0.0 only

Published 2020-05-20. Last modified 2026-06-17.