THREAT OPS › Threat News › [GHSA] GHSA-5vf6-jrqr-78fj (medium) — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
[GHSA] GHSA-5vf6-jrqr-78fj (medium) — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
GHSA-5vf6-jrqr-78fj Severity: medium CVE: CVE-2026-63004
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
## Summary
Unleash's addon/integration subsystem lets an operator configure a webhook (and the Slack, Microsoft Teams, Datadog, and New Relic integrations)
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-63004cve
- http://169.254.169.254/latest/meta-data/…`url
- http://127.0.0.1:url
- http://some-url.comurl
- http://127.0.0.1:${port}`url
- http://169.254.169.254/latest/url
- http://127.0.0.1:1/url
- http://169.254.169.254/latest/meta-data/iam/security-credentials/url
- attacker@evil.comemail
- 127.0.0.0/8cidr
- 169.254.0.0/16cidr
Original source: https://github.com/advisories/GHSA-5vf6-jrqr-78fj