Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63004— Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

CVSS 5.5 · Medium EPSS 0.27% · P20

Affected Version Matrix 3

VendorProductVersion RangeStatus
Unleashunleash< 7.5.2affected
>= 7.6.0, < 7.6.5affected
>= 8.0.0, < 8.0.2affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-63004

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Source: CVE Program / CVE List V5
Vulnerability Description
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to Addon.fetchRetry in src/lib/addons/addon.ts without restricting loopback, link-local, private, or cloud metadata addresses. An authenticated actor with the root CREATE_ADDON or UPDATE_ADDON permission can cause the server to send requests from inside its network boundary, use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an attacker-observed host, and deliver the feature-event JSON body to internal services. This issue is fixed in versions 7.5.2, 7.6.5, and 8.0.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Unleashunleash < 7.5.2 -

II. Public POCs for CVE-2026-63004

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63004

登录查看更多情报信息。

Vendor Advisories for CVE-2026-63004 (1)

Vendor Pages for CVE-2026-63004 (3)

Same Patch Batch · Unleash · 2026-08-21 · 3 CVEs total

CVE-2026-634627.5 HIGHUnleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
CVE-2026-634664.1 MEDIUMUnleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Sla

IV. Related Vulnerabilities

V. Comments for CVE-2026-63004

No comments yet


Leave a comment