GCP-2026-034
Cybersecurity Classified by Officially
Published: 2026-05-20
Description
Description Severity NotesA vulnerability was found in Apigee where the IntegrationRegion parameter in the SetIntegrationRequest policy lacks validation, allowing for Server-Side Request Forgery (SSRF) and service account token exfiltration. The issue arises when an attacker can control a flow variable used for IntegrationRegion, leading to requests being sent to an attacker-controlled host with the service account token.
This is an extract. The publication continues at the source.
Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-034
Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Google — imported from official source
- Official source
- https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-034