Server-Side Request Forgery Vulnerability in Apioo Fusio by Apioo
CVE-2026-72598
6.5MEDIUM
What is CVE-2026-72598?
A server-side request forgery vulnerability exists in Apioo Fusio version 8.8.3, which allows authenticated users with consumer roles to exploit webhook functionality. By registering an internal host URL within a webhook registration endpoint that inadequately validates the host against a denylist, attackers can trigger unauthorized HTTP requests to internal network addresses. This oversight enables potential information disclosure and further attacks on internal systems.
Affected Version(s)
Fusio 0 <= 8.8.3
