CVE-2026-80350

HIGHPre-NVD 7.17.1
EchelonGraph scoreMEDIUM confidence

This high-severity CVE scores 7.1 under the CNA's CVSS (NVD's own analysis pending). EPSS exploit probability: 0.3%, top 79% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: cna:vulncheck, epss
Trending — 3 sources updated this weekElevated
7.1EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.1Exploit: Elevated riskExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIsSafe, and the host-literal screening inside Common/Server/Utils/SSRFProtection.ts, performed by isBlockedHostnameLiteral, rejects private and loopback IPv4 ranges and tests an IPv6 value against the unspecified address, the loopback, the link-local prefix and the unique-local prefixes. A value such as [::ffff:127.0.0.1] matches none of them. The value is also recognised as an address literal rather than a name, so the path that re-checks addresses obtained from resolution is not taken. The HTTP client treats the mapped form as the embedded IPv4 address and connects to it, so an authenticated project member who can configure a webhook can direct the server at loopback services, private network ranges and link-local metadata endpoints, and the response is recorded where the webhook result can be read. Version 12.0.7 adds handling for the mapped range.

CVSS v3
7.1
EG Score
7.1(medium)
EG Risk
48(Track)
EG Risk 48/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity71% × 45%
Exploitation40% × 40%
Automatability0% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
21%
KEV
Not listed

Published

August 26, 2026

Last Modified

August 29, 2026

Advisory Details (5)

Auto-updated Aug 26, 2026
🔬 Proof of concept available. Patch available. Sources: github.
generic

OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL | Advisories | VulnCheck

https://www.vulncheck.com/advisories/oneuptime-before-12.0.7-server-side-request-forgery-via-ipv4-mapped-ipv6-webhook-url
generic

oneuptime/Common/Server/Utils/SSRFProtection.ts at 12.0.6 · OneUptime/oneuptime · GitHub

https://github.com/OneUptime/oneuptime/blob/12.0.6/Common/Server/Utils/SSRFProtection.ts
generic

SSRF via IPv4-Mapped IPv6 Bypass in Webhook URL Validation · Issue #2578 · OneUptime/oneuptime · GitHub

https://github.com/OneUptime/oneuptime/issues/2578
github Patch Available🟡 PoC Available

SSRF via IPv4-Mapped IPv6 Bypass in Webhook URL Validation · Advisory · OneUptime/oneuptime · GitHub

https://github.com/OneUptime/oneuptime/security/advisories/GHSA-9g3w-r349-3vvw
generic

GitHub - OneUptime/oneuptime: Complete open-source monitoring and observability platform. · GitHub

https://github.com/OneUptime/oneuptime

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 10× in last 7d / 10× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 01:22 UTCEPSS rescore
  2. 2026-08-29 11:59 UTCEG score recompute
  3. 2026-08-29 05:48 UTCEG score recompute
  4. 2026-08-28 21:42 UTCEPSS rescore
  5. 2026-08-27 16:37 UTCEG score recompute
  6. 2026-08-27 14:25 UTCEPSS rescore
  7. 2026-08-26 15:53 UTCEG score recompute
  8. 2026-08-26 14:08 UTCEG score recompute
  9. 2026-08-26 10:18 UTCEG score recompute
  10. 2026-08-26 10:17 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-80350?
CVE-2026-80350 is a high vulnerability published on August 26, 2026. OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIsSafe, and the host-literal screening inside…
When was CVE-2026-80350 disclosed?
CVE-2026-80350 was first published in the National Vulnerability Database on August 26, 2026, with the most recent update on August 29, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-80350 actively exploited?
CVE-2026-80350 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 79.4% of all scored CVEs.
What is the CVSS score of CVE-2026-80350?
CVE-2026-80350 has a CVSS v4.0 base score of 7.1 (CNA self-assessment; NVD's own analysis pending).
How do I remediate CVE-2026-80350?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-80350, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-80350

Explore →

Is Your Infrastructure Affected by CVE-2026-80350?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.