Skip to main content
CRITICAL

CVE-2022-1379

CVSS v3

9.1

CRITICAL

EPSS Score

1.6 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.

Technical details

Published
2022-05-14

Frequently asked questions

What is CVE-2022-1379?

URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.

Is CVE-2022-1379 actively exploited?

Active exploitation of CVE-2022-1379 has not been confirmed. Its EPSS score was 1.6% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-1379?

CVE-2022-1379 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2022-1379 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key