CVE-2026-108602
Last modified
CVE-2026-108602 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services..
Description
Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-108602?
How severe is CVE-2026-108602?
How do I fix CVE-2026-108602?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-108597Cohere Python SDK 5.11.0 through 7.2.0 contains a path trave…4.8
- CVE-2026-108598Floci 1.1.0 before 2.2.0 contains a code injection vulnerabi…9.8
- CVE-2026-108599phi 0.1.1 through 0.28.4 contains an improper link resolutio…4.7
- CVE-2026-1086The Font Pairing Preview For Landing Pages plugin for WordPr…4.3
- CVE-2026-10860A logic error in the MISP CRUD component delete handler allo…6.5
- CVE-2026-108600open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21…4.7
- CVE-2026-108603slide-maker through 5.8.0 contains a path traversal vulnerab…3.3
- CVE-2026-108604Tabularis through 0.27.0 contains an incorrect authorization…6.3
- CVE-2026-108605JeecgBoot through 3.9.5 contains a missing authorization vul…4.3
- CVE-2026-108606JeecgBoot through 3.9.5 contains a missing authorization vul…5.4
- CVE-2026-108607JeecgBoot through 3.9.5 contains an insecure direct object r…4.3
- CVE-2026-108608JeecgBoot through 3.9.5 contains an insecure direct object r…4.3
Are you affected by CVE-2026-108602?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
