CVE-2026-82957 | hyperledger-firefly up to 1.4.0 Webhook Subscription webhooks.go ValidateOptions url server-side request forgery
A vulnerability classified as critical has been found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery.
This vulnerability is known as CVE-2026-82957. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More