CVE-2024-2796: Akana API Platform
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.
Affected products
- Akana Akana API Platform: from 2022.1.1, before 2022.1.1 (CVE-2024-2796 Patch) (fixed in 2022.1.1 (CVE-2024-2796 Patch)); from 2022.1.2, before 2022.1.2 (CVE-2024-2796 Patch) (fixed in 2022.1.2 (CVE-2024-2796 Patch)); from 0.0.0, before 2024.1.0 (fixed in 2024.1.0); from 0.0.0, before 2022.1.3.2 (fixed in 2022.1.3.2); from 2022.1.1, before 2022.1.1 (fixed in 2022.1.1); from 2022.1.2, before 2022.1.2 (fixed in 2022.1.2); …
Published 2024-04-18. Last modified 2026-06-17.