Webhook URL Validation Vulnerability in Memos by UseMemos
CVE-2026-71271
8.5HIGH
What is CVE-2026-71271?
A vulnerability exists in the webhook URL validation of Memos, where the validation process incorrectly handles certain IP addresses, particularly 0.0.0.0/8. This oversight allows attackers to register malicious webhook URLs by directing requests to this special IP address. This could lead the Memos server to execute outbound requests to its own loopback interface, inadvertently exposing internal services intended to be isolated from external access. Proper validation measures are essential to prevent potential exploitation and ensure the security of internal networks.
Affected Version(s)
memos 0 <= 0.29.1
