Server-Side Request Forgery in Grav API Plugin by Grav
CVE-2026-56708
6.9MEDIUM
What is CVE-2026-56708?
The Grav API plugin prior to version 1.0.16 is susceptible to a server-side request forgery (SSRF) vulnerability affecting webhook delivery processes. This flaw allows attackers to exploit DNS rebinding techniques to circumvent hostname validation, enabling them to manipulate validation lookups. By controlling the authoritative DNS server for a designated webhook hostname, attackers can respond to these validation requests with public IP addresses while supplying private IP addresses during delivery lookups, which may permit unauthorized access to sensitive internal network resources.
Affected Version(s)
grav 0 < 1.0.16
grav 1.0.16
