Vulnerabilities & PatchesEmerging1 src
CVE-2026-76838 - Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook Redirects
CVE ID : CVE-2026-76838
Published : Aug. 24, 2026, 6:17 p. m.
• 54 minutes ago
Description : Hi. Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule. php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes.
At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without repeating the check, and backend/config/webhook-server. php sets no Guzzle options, so redirect following remains enabled by default.
A destination that answers with a redirect to a loopback, private or cloud metadata address therefore causes the server to issue that request, and changing the hostname's DNS record after registration reaches the same result because no resolution is repeated.