Server-Side Request Forgery in OneUptime Affects Webhook Configuration
CVE-2026-80350

7.1HIGH

Key Information:

Vendor

Oneuptime

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80350?

The vulnerability in OneUptime's webhook configuration allows for server-side request forgery (SSRF) due to the incorrect handling of private and loopback addresses in IPv4-mapped IPv6 form. An attacker with valid project member credentials can exploit this flaw to direct webhook requests to internal services, bypassing network safeties. This issue is linked to the failure of the validation process within the SSRFProtection module, which fails to block certain address formats. As a result, responses from sensitive internal endpoints can be accessed if configured in a webhook. The defect is resolved in version 12.0.7 by implementing proper handling for IPv4-mapped addresses.

Affected Version(s)

OneUptime 0 < 12.0.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.