CVE-2023-40148: Ping Identity Pingfederate

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.

Affected products

  • Ping Identity Pingfederate: from 11.3.0, up to and including 11.3.2; from 11.2.0, up to and including 11.2.7; from 11.1.0, up to and including 11.1.8; from 11.0.0, up to and including 11.0.8
  • Pingidentity Pingfederate: from 11.0.0, up to and including 11.0.8; from 11.1.0, up to and including 11.1.8; from 11.2.0, up to and including 11.2.7; from 11.3.0, up to and including 11.3.2

Published 2024-04-10. Last modified 2026-06-17.