firefighter-incident
FireFighter is an incident management application, designed to work in Slack, and more.
Activity
- Latest release
- 4d ago
- Total releases
- 73
- Cadence
- ~2 days
- Last 12 months
- 57
Reach
- Stars
- 25
Details
- License
- custom
- First release
- Jan 25, 2024
| Version | Released | |
|---|---|---|
0.0.72
patch
| ||
0.0.71
patch
| ||
0.0.70
patch
| ||
0.0.69
patch
| ||
0.0.68
patch
| ||
0.0.67
patch
| ||
0.0.65
patch
| ||
0.0.64
patch
| ||
0.0.63
patch
| ||
0.0.62
patch
| ||
0.0.61
patch
| ||
0.0.60
patch
| ||
0.0.59
patch
| ||
0.0.58
patch
| ||
0.0.57
patch
| ||
0.0.56
patch
| ||
0.0.55
patch
| ||
0.0.54
patch
| ||
0.0.53
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.52
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.51
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.50
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.49
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.48
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.47
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.46
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.45
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.44
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.43
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.42
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.41
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.40
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.39
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.38
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.37
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.36
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.35
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.34
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.33
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.32
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.31
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.30
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.29
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.28
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.27
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.26
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.25
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.24
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.23
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.22
patch
1 CVE
CVE-2026-42864
PYSEC-2026-339
GHSA-fqvv-jvhr-g5jc
Jun 29, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
9.9
/ 10
Critical
Network
Low
None
None
Changed
High
Low
Low
ImpactThe An unauthenticated caller able to reach the ingress can coerce the pod into
fetching arbitrary URLs — including the cloud metadata endpoint at
On EC2/EKS deployments that do not enforce IMDSv2, this allows theft of the temporary AWS credentials attached to the pod's IAM role. The docstring on the view claims a Bearer token is required, but the code does not enforce it. Affected code paths:
PatchesFixed in
Users should upgrade to WorkaroundsUntil upgrade is possible, any one of the following blocks end-to-end exploitation:
Resources
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.1rc1
+ 43 more Show less
0.0.1rc2
0.0.2
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.3
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.4
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.5
0.0.50
0.0.51
0.0.52
0.0.53
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.54
References
Updated Jul 01, 2026 · Source: OSV.dev |