CVE-2022-26499: Debian Linux
Critical severity, CVSS 9.1. EPSS: 7.7% chance of exploitation in the next 30 days.
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only
- Digium Asterisk: from 16.15.0, up to and including 16.25.1; from 18.0, before 18.11.2 (fixed in 18.11.2); from 19.0.0, up to and including 19.3.1
Published 2022-04-15. Last modified 2026-06-17.