CVE-2026-80350 – OneUptime
CVSS 7.1
IMPORTANT
Zero Day – Immediate Deployment
“A crafted webhook target can bypass SSRF protections and expose internal services or cloud metadata.”
OneUptime contains a High-severity server-side request forgery vulnerability in webhook target validation. CVE-2026-80350 allows an authenticated project member to use IPv4-mapped IPv6 addresses to bypass protections that normally block loopback, private network, and link-local destinations. This can make the OneUptime server connect to internal services or metadata endpoints and expose returned responses. The CVSS score is 7.1, which is High severity.
The issue is fixed in OneUptime 12.0.7. Public proof-of-concept material is available.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-918
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.