Server-Side Request Forgery Vulnerabilities in Heym Products by Heym
CVE-2026-100863

5.3MEDIUM

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100863?

Heym versions 0.0.90 and earlier are susceptible to two critical server-side request forgery (SSRF) vulnerabilities. The first vulnerability arises from an inadequately secured LLM image-edit input loader, which employs a basic HTTP request method that fails to ensure robust egress restriction. This creates a risk where an API caller could manipulate the image URL input, allowing unintended HTTP requests to internal resources like loopback addresses or cloud metadata. The second issue pertains to inadequate IPv6 address validation, which permits certain IPv6 address formats to pass through initial security checks, potentially leading to the exposure of private network resources. The vulnerability has been addressed in version 0.0.91, which implements enhanced security measures such as routing through a protected client and rejecting risky address formats.

Affected Version(s)

heym 0 < 0.0.91

heym 0.0.91

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.