Server-Side Request Forgery in Hyperledger Firefly Webhook Subscription
CVE-2026-82957

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82957?

A server-side request forgery vulnerability has been identified in Hyperledger Firefly's Webhook Subscription component. The issue lies in the ValidateOptions function found in the internal/events/webhooks/webhooks.go file. An attacker can manipulate the URL argument, potentially leading to unauthorized remote requests being executed by the server. This flaw poses a significant risk as it can be exploited remotely, allowing attackers to interact with internal resources inappropriately. Despite early notification, the vendor did not respond to the disclosure of this vulnerability, increasing the urgency for users to secure their systems to prevent exploitation.

Affected Version(s)

firefly 1.0

firefly 1.1

firefly 1.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Alves (VulDB User)
VulDB CNA Team
.