Server-Side Request Forgery in Hi.Events Affects Webhook Validation
CVE-2026-76838
What is CVE-2026-76838?
Hi.Events contains a vulnerability that enables server-side request forgery (SSRF) through the unvalidated redirects of webhooks. The system initially validates webhook destinations upon registration but fails to re-validate when these URLs are utilized for dispatch. This oversight allows malicious actors to manipulate the registered URLs, potentially redirecting requests to internal or private networks and inadvertently exposing sensitive data. The lack of stringent checks during the dispatch process mitigates security, as redirect responses may not be discarded, thus logging the internal service’s response inappropriately. The vulnerability affects all versions before 1.11.1-beta, which introduces necessary validation improvements.
Affected Version(s)
Hi.Events 0 < 1.11.1-beta
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
