VDB
GCVE-110-CLOUD-2025-0132
GCVE-110-CLOUD-2025-0132
Advisory Published
Three SSRF vulnerabilities were discovered in Azure DevOps, allowing access to internal metadata endpoints and potential CRLF injection. The issues affected the endpointproxy and Service Hooks functionality. DNS rebinding could bypass initial fixes. Microsoft awarded $15,000 in bug bounties for the findings.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Azure | DevOps | — | — |
References
Finding SSRFs in Azure DevOps
advisory
Browse GCVE Records
67,954 records in the GCVE database · Updated August 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.