Server-Side Request Forgery in Hi.Events Affects Webhook Validation
CVE-2026-76838

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-76838?

Hi.Events contains a vulnerability that enables server-side request forgery (SSRF) through the unvalidated redirects of webhooks. The system initially validates webhook destinations upon registration but fails to re-validate when these URLs are utilized for dispatch. This oversight allows malicious actors to manipulate the registered URLs, potentially redirecting requests to internal or private networks and inadvertently exposing sensitive data. The lack of stringent checks during the dispatch process mitigates security, as redirect responses may not be discarded, thus logging the internal service’s response inappropriately. The vulnerability affects all versions before 1.11.1-beta, which introduces necessary validation improvements.

Affected Version(s)

Hi.Events 0 < 1.11.1-beta

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@tonghuaroot
@de3erve
Jaime RamĂ­rez (@JaimeRamirez-coder)
@senti-man
@angelystor
@1amplant
@tikket1
@Fewword
@dizconnectz
.