Server-Side Request Forgery in Helicone Webhook Sender Affects Jawn Users
CVE-2026-108602

5.3MEDIUM

Key Information:

Vendor

Helicone

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108602?

The Helicone product version v2025.08.21-1 features a server-side request forgery vulnerability specifically within the Jawn webhook sender. This issue allows authenticated users of the organization to exploit the system by crafting webhooks that utilize public hostnames, which can then resolve to private internal addresses. Consequently, this opens up the potential for attackers to send blind POST requests to sensitive internal HTTPS services, significantly increasing the risk of unauthorized data access and exploitation of internal systems.

Affected Version(s)

helicone 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.