PT-2026-79421 · Unleash · Unleash
CVE-2026-63004
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Unleash versions prior to 7.5.2
Unleash versions prior to 7.6.5
Unleash versions prior to 8.0.2
Description
The addon and integration subsystem fails to restrict loopback, link-local, private, or cloud metadata addresses when passing the
parameters.url value from src/lib/addons/webhook.ts and integrations for Slack, Microsoft Teams, Datadog, and New Relic to the Addon.fetchRetry() function in src/lib/addons/addon.ts. An authenticated actor with CREATE ADDON or UPDATE ADDON permissions can exploit this to perform Server-Side Request Forgery (SSRF), causing the server to send requests from within its network boundary. This allows the actor to use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an external host, and deliver feature-event JSON bodies to internal services.Recommendations
Update to version 7.5.2.
Update to version 7.6.5.
Update to version 8.0.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unleash