7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Description
CVE-2026-34207 The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets. Intro I found this issue while reviewing...
Basic Information
ID
E61DF141-B3A8-537B-8845-233051D12F82
Published
Jun 26, 2026 at 12:45
Modified
Jun 26, 2026 at 12:46