CVE-2020-15879: Bitwarden Server
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
Affected products
- Bitwarden Server: version 1.35.1 only
Published 2020-07-21. Last modified 2026-06-17.