CVE-2026-63004
Last modified
CVE-2026-63004 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to Addon.fetchRetry in src/lib/addons/addon.ts without restricting loopback, link-local, private, or cloud metadata addresses. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to Addon.fetchRetry in src/lib/addons/addon.ts without restricting loopback, link-local, private, or cloud metadata addresses. An authenticated actor with the root CREATE_ADDON or UPDATE_ADDON permission can cause the server to send requests from inside its network boundary, use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an attacker-observed host, and deliver the feature-event JSON body to internal services. This issue is fixed in versions 7.5.2, 7.6.5, and 8.0.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unleash | unleash | < 7.5.2; >= 7.6.0, < 7.6.5; >= 8.0.0, < 8.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63004?
How severe is CVE-2026-63004?
How do I fix CVE-2026-63004?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62994CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14…3.7
- CVE-2026-62995joserfc is a Python library that provides an implementation …2.3
- CVE-2026-62996Smarty is a template engine for PHP, facilitating the separa…6.9
- CVE-2026-62999Copier is a library and CLI app for rendering project templa…7.5
- CVE-2026-6300Use after free in CSS in Google Chrome prior to 147.0.7727.1…8.8
- CVE-2026-63003django CMS is an easy-to-use and developer-friendly enterpri…6.5
- CVE-2026-6301Type Confusion in Turbofan in Google Chrome prior to 147.0.7…8.8
- CVE-2026-63015Uncontrolled Resource Consumption vulnerability in Apache In…4.3
- CVE-2026-63016Uncontrolled Resource Consumption vulnerability in Apache In…5.3
- CVE-2026-6302Use after free in Video in Google Chrome prior to 147.0.7727…8.8
- CVE-2026-63020A vulnerability exists in an undisclosed BIG-IP Configuratio…3.1
- CVE-2026-6303Use after free in Codecs in Google Chrome prior to 147.0.772…8.8
Are you affected by CVE-2026-63004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
