PT-2026-79421 · Unleash · Unleash

CVE-2026-63004

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Unleash versions prior to 7.5.2 Unleash versions prior to 7.6.5 Unleash versions prior to 8.0.2
Description The addon and integration subsystem fails to restrict loopback, link-local, private, or cloud metadata addresses when passing the parameters.url value from src/lib/addons/webhook.ts and integrations for Slack, Microsoft Teams, Datadog, and New Relic to the Addon.fetchRetry() function in src/lib/addons/addon.ts. An authenticated actor with CREATE ADDON or UPDATE ADDON permissions can exploit this to perform Server-Side Request Forgery (SSRF), causing the server to send requests from within its network boundary. This allows the actor to use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an external host, and deliver feature-event JSON bodies to internal services.
Recommendations Update to version 7.5.2. Update to version 7.6.5. Update to version 8.0.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63004
GHSA-5VF6-JRQR-78FJ

Affected Products

Unleash