CVE-2026-82957 | hyperledger-firefly up to 1.4.0 Webhook Subscription webhooks.go ValidateOptions url server-side request forgery

SecurityVulns

A vulnerability classified as critical has been found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery.

This vulnerability is known as CVE-2026-82957. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More