SSRF Vulnerability in Webhook Validator of Affected Web Application
CVE-2026-72761

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72761?

The webhook URL validator in the affected web application improperly validates DNS resolution, allowing attackers to exploit this weakness. By utilizing specific IPv6 transition addresses, an attacker can register a malicious webhook that resolves to a vulnerable internal endpoint. This enables potential data exfiltration, bypassing the intended security measures. The vulnerability has been addressed in the latest development version, and users are advised to update their systems promptly.

Affected Version(s)

vulnerability-lookup 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
Cedric Bonhomme
.