CVE-2026-16127 | zevorn rt-claw up to 0.2.0 http_request claw/tools/tool_net.c claw_net_get/claw_net_post url server-side request forgery (Issue 139 / EUVD-2026-45388)
A vulnerability was found in zevorn rt-claw up to 0.2.0 and classified as critical. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery.
This vulnerability is listed as CVE-2026-16127. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.