CVE-2025-58441 - CVE House
Back to Database
Status published Medium CVE-2025-58441

Knowage is vulnerable to blind server-side request forgery (SSRF)

Vulnerability Description

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58441

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

KnowageLabs

View all reports →

Affected Software

Knowage-Server
Vulnerable Versions:
< 8.1.37

Timeline

Official Publish: January 7th, 2026
Last Modified: January 7th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)