Webhook URL Manipulation in Novu Notification API by Novu
CVE-2026-75511
5.3MEDIUM
What is CVE-2026-75511?
The Novu Notification API allows users to send notifications through various channels. Versions before 3.18.0 are vulnerable to a manipulation issue involving webhook URLs. This flaw enables authenticated users to substitute internal or restricted URLs, bypassing crucial security measures like URL normalization and DNS pinning. As a result, attackers can direct POST requests to sensitive internal services, potentially leading to unauthorized interactions with those services. This vulnerability has been patched in version 3.18.0.
Affected Version(s)
api-service < 3.18.0
novu < 3.18.0
