Server-Side Request Forgery Vulnerability in HyperDX by HyperDX
CVE-2026-63730

5.3MEDIUM

Key Information:

Vendor

Hyperdxio

Status
Vendor
CVE Published:
20 July 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-63730?

HyperDX prior to version 2.31.0 is vulnerable to a server-side request forgery (SSRF) attack. Authenticated team members can manipulate the server to send requests to arbitrary internal network destinations by crafting specific URLs for the webhook test endpoint. This vulnerability allows attackers to bypass hostname blacklist validation checks within the webhook handler, potentially providing them access to internal services, containers, or even sensitive cloud instance metadata, including provider metadata endpoints.

Affected Version(s)

hyperdx 2.0.0 < 2.31.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.