THREAT OPS › Threat News › [GHSA] GHSA-rg5q-pp8p-f7jm (high) — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
[GHSA] GHSA-rg5q-pp8p-f7jm (high) — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
GHSA-rg5q-pp8p-f7jm Severity: high CVE: CVE-2026-55537
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
### Summary
`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook URLs by resolving the hostname and checking whether the IP is private. When DNS resolution fails (`socket.gaierror`), the validato
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-40114cve
- CVE-2026-55537cve
- http://rebind.attacker.com/cburl
- http://rebind.attacker.com/callbackurl
- http://rebind.attacker.com/callback`url
- http://praisonai-server:8000/jobsurl
Original source: https://github.com/advisories/GHSA-rg5q-pp8p-f7jm