PT-2026-38445 · Wallos · Wallos

·

CVE-2026-41688

·

Published

2026-05-07

·

Updated

2026-05-07

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.8.5
Description An incomplete Server-Side Request Forgery (SSRF) fix allows for a DNS rebinding Time-of-Check to Time-of-Use (TOCTOU) window. The application validates webhook URLs using the gethostbyname() function but subsequently passes the original hostname to cURL without using CURLOPT RESOLVE pinning across 10 of 11 outbound HTTP endpoints. DNS rebinding is a technique used to bypass Same-Origin Policy restrictions by changing the IP address associated with a domain name between the time of validation and the time of use.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41688
GHSA-H4G7-XV3V-Q73G

Affected Products

Wallos