CVE-2026-100863 | heymrun Heym up to 0.0.90 SSRF Guard ssrf_guard.py _load_image_bytes/_is_public_address userInput server-side request forgery
A vulnerability described as problematic has been identified in heymrun Heym up to 0.0.90. Impacted is the function _load_image_bytes/_is_public_address of the file app/services/ssrf_guard.py of the component SSRF Guard. Executing a manipulation of the argument userInput can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-100863. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More