THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5vf6-jrqr-78fj (medium) — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

[GHSA] GHSA-5vf6-jrqr-78fj (medium) — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

highgithub_advisoriesPublished 2026-08-21

GHSA-5vf6-jrqr-78fj Severity: medium CVE: CVE-2026-63004

Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

## Summary

Unleash's addon/integration subsystem lets an operator configure a webhook (and the Slack, Microsoft Teams, Datadog, and New Relic integrations)

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5vf6-jrqr-78fj