Server-Side Request Forgery in Grav API Plugin by Grav
CVE-2026-56708

6.9MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-56708?

The Grav API plugin prior to version 1.0.16 is susceptible to a server-side request forgery (SSRF) vulnerability affecting webhook delivery processes. This flaw allows attackers to exploit DNS rebinding techniques to circumvent hostname validation, enabling them to manipulate validation lookups. By controlling the authoritative DNS server for a designated webhook hostname, attackers can respond to these validation requests with public IP addresses while supplying private IP addresses during delivery lookups, which may permit unauthorized access to sensitive internal network resources.

Affected Version(s)

grav 0 < 1.0.16

grav 1.0.16

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.