Preface Apache ShenYu is a Java native API Gateway for service proxy, protocol conversion and API governance. Description Numen Cyber Labs vulnerability researchers have discovered an SSRF vulnerability in Apache ShenYu< version 2.6. CVE ID CVE-2023–25753 Impacts version < 2.6 Analysis org.apache.shenyu.admin.controller.SandboxController#proxyGateway receives proxyGatewayDTO, calls requestProxyGateway method ProxyGatewayDTO has requestUrl, cookie, headers, httpMethod parameters requestProxy...