CVE-2026-7306: Impl Xxljobserviceimpl Java Cwe 918 Cve 2026 7306

Missing validation of the user-supplied addressList business parameter against the registered base addresses for the target job group, leading to SSRF.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Javaβ
greprules fetch cve-2026-7306-impl-xxljobserviceimpl-java-cwe-918-cve-2026-7306 --engine opengrep

Description

Missing validation of the user-supplied addressList business parameter against the registered base addresses for the target job group, leading to SSRF.