Threats Tagged 'ghsa-q8pq-98hq-mg7f'
View all threats tagged with 'ghsa-q8pq-98hq-mg7f'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-q8pq-98hq-mg7f'
Click on any threat for detailed analysis and mitigation recommendations
Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that… (CVE-2026-71250)CVE-2026-71250 0 Firefly III's webhook URL validator improperly handles loopback IP addresses and DNS resolution, allowing authenticated users with webhooks enabled to configure webhooks targeting internal loopback services. The validator permits addresses in the 127.0.0.0/8 range due to an early return and performs hostname resolution only once at validation, while the actual webhook request re-resolves the hostname, enabling DNS rebinding attacks. The vulnerability results in a blind server-side request forgery (SSRF) without direct response feedback to the user. Join the discussion | GCVE Database | 08/05/2026, 12:31:32 UTC Added: 08/05/2026, 15:31:22 UTC |
Showing 1 to 1 of 1 result