{"id":"CVE-2022-26499","details":"An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.","modified":"2026-07-11T03:54:06.462117406Z","published":"2022-04-15T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26499.json","unresolved_ranges":[{"extracted_events":[{"fixed":"19.x"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/166745/Asterisk-Project-Security-Advisory-AST-2022-002.html"},{"type":"WEB","url":"https://downloads.asterisk.org/pub/security/"},{"type":"WEB","url":"https://downloads.asterisk.org/pub/security/AST-2022-002.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26499.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26499"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5285"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"b240b843312850b724c5a37340d61101a613d8d1"},{"introduced":"2c1bba3cbec008c8ce35c78a2c79f9f207ea58bc"},{"fixed":"3e57d107467db7b5e4b64db75edf09641881c9fd"},{"introduced":"de4f63b4824c91a0cd9f3d95f3b7923bec71960c"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"16.15.0"},{"last_affected":"16.25.1"},{"introduced":"18.0"},{"fixed":"18.11.2"},{"introduced":"19.0.0"},{"last_affected":"19.3.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-26499.json"}}],"schema_version":"1.7.5"}