← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 18:17via CVEFeed

CVE-2026-76838 - Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook Redirects

Brief

CVE ID : CVE-2026-76838

Published : Aug. 24, 2026, 6:17 p. m.

  • 54 minutes ago

Description : Hi. Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule. php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes.

At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without repeating the check, and backend/config/webhook-server. php sets no Guzzle options, so redirect following remains enabled by default.

A destination that answers with a redirect to a loopback, private or cloud metadata address therefore causes the server to issue that request, and changing the hostname's DNS record after registration reaches the same result because no resolution is repeated.

Read more on CVEFeed