Server-Side Request Forgery in OneUptime Affects Webhook Configuration
CVE-2026-80350
7.1HIGH
What is CVE-2026-80350?
The vulnerability in OneUptime's webhook configuration allows for server-side request forgery (SSRF) due to the incorrect handling of private and loopback addresses in IPv4-mapped IPv6 form. An attacker with valid project member credentials can exploit this flaw to direct webhook requests to internal services, bypassing network safeties. This issue is linked to the failure of the validation process within the SSRFProtection module, which fails to block certain address formats. As a result, responses from sensitive internal endpoints can be accessed if configured in a webhook. The defect is resolved in version 12.0.7 by implementing proper handling for IPv4-mapped addresses.
Affected Version(s)
OneUptime 0 < 12.0.7
