Webhook URL Validation Vulnerability in Memos by UseMemos
CVE-2026-71271

8.5HIGH

Key Information:

Vendor

Usememos

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71271?

A vulnerability exists in the webhook URL validation of Memos, where the validation process incorrectly handles certain IP addresses, particularly 0.0.0.0/8. This oversight allows attackers to register malicious webhook URLs by directing requests to this special IP address. This could lead the Memos server to execute outbound requests to its own loopback interface, inadvertently exposing internal services intended to be isolated from external access. Proper validation measures are essential to prevent potential exploitation and ensure the security of internal networks.

Affected Version(s)

memos 0 <= 0.29.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.