Open-Source Feature Management Platform Vulnerability in Unleash by Unleash
CVE-2026-63004
5.5MEDIUM
What is CVE-2026-63004?
Unleash, an open-source feature management platform, has a vulnerability in its addon and integration subsystem. Authenticated users with specific permissions can manipulate parametric values. This vulnerability allows them to bypass restrictions on loopback and link-local addresses, potentially causing internal servers to send unauthorized requests. The affected versions failed to safeguard sensitive integration details, leading to possible exposure of API keys and custom headers. The issue was resolved in versions 7.5.2, 7.6.5, and 8.0.2.
Affected Version(s)
unleash < 7.5.2 < 7.5.2
unleash >= 7.6.0, < 7.6.5 < 7.6.0, 7.6.5
unleash >= 8.0.0, < 8.0.2 < 8.0.0, 8.0.2
