SSRF Vulnerability in heym Integration Services by heymrun
CVE-2026-100861

5.3MEDIUM

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100861?

The vulnerability in heym prior to version 0.0.105 allows authenticated users to bypass server-side request forgery (SSRF) protections. This occurs due to the failure to enforce egress guards on integration services that utilize base URLs supplied through credentials. Malicious actors can manipulate these credentials to direct requests to loopback, private, or cloud-metadata addresses, thus gaining unauthorized access to internal service responses. This flaw poses significant risks to data confidentiality and system integrity.

Affected Version(s)

heym 0 < 0.0.105

heym 0.0.105

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

fatihkaratash
mbakgun
.