CVE-2026-42858 | openedx openedx-platform up to 169.254.169.254 Internal Network Service requests.get metadata_url server-side request forgery
A vulnerability classified as critical has been found in openedx openedx-platform up to 169.254.169.254. This affects the function requests.get of the component Internal Network Service Handler. This manipulation of the argument metadata_url causes server-side request forgery.
This vulnerability appears as CVE-2026-42858. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.