CVE-2020-11987EPSS p96.3%
CVE-2020-11987CVE-2020-11987
apache / batik
Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Scoring
| CVSS | 8.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 13.28% probability of exploitation · percentile 96.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |