CVE-2026-80350 – OneUptime

CVSS 7.1 IMPORTANT Zero Day – Immediate Deployment

“A crafted webhook target can bypass SSRF protections and expose internal services or cloud metadata.”

OneUptime contains a High-severity server-side request forgery vulnerability in webhook target validation. CVE-2026-80350 allows an authenticated project member to use IPv4-mapped IPv6 addresses to bypass protections that normally block loopback, private network, and link-local destinations. This can make the OneUptime server connect to internal services or metadata endpoints and expose returned responses. The CVSS score is 7.1, which is High severity.

The issue is fixed in OneUptime 12.0.7. Public proof-of-concept material is available.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-918
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.