CVE-2026-26957

Source
https://cve.org/CVERecord?id=CVE-2026-26957
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26957.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26957
Aliases
Downstream
Related
Published
2026-02-19T23:30:48.166Z
Modified
2026-03-04T22:28:55.593243Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Libredesk has an SSRF Vulnerability via Webhooks
Details

Libredesk is a self-hosted customer support desk application. Versions prior to 1.0.2-0.20260215211005-727213631ce6 fail to validate destination URLs for webhooks, allowing an attacker posing as an authenticated "Application Admin" to force the server to make HTTP requests to arbitrary internal destinations. This could compromise the underlying cloud infrastructure or internal corporate network where the service is hosted. This issue has been fixed in version 1.0.2-0.20260215211005-727213631ce6.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26957.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-209",
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/abhinavxd/libredesk

Affected ranges

Type
GIT
Repo
https://github.com/abhinavxd/libredesk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1.0-alpha
v0.1.1-alpha
v0.10.0-beta
v0.11.0-beta
v0.11.1-beta
v0.2.1-alpha
v0.3.0-alpha
v0.3.1-alpha
v0.3.2-alpha
v0.3.3-alpha
v0.4.0-alpha
v0.4.1-alpha
v0.4.2-alpha
v0.4.3-alpha
v0.5.0-alpha
v0.6.0-alpha
v0.7.0-alpha
v0.7.1-alpha
v0.7.2-alpha
v0.7.3-alpha
v0.7.4-alpha
v0.8.0-beta
v0.8.1-beta
v0.8.2-beta
v0.8.3-beta
v0.8.4-beta
v0.8.5-beta
v0.8.6-beta
v0.9.1-beta
v0.9.2-beta
v0.9.3-beta
v0.9.4-beta
v0.9.5-beta
v1.*
v1.0.0
v1.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26957.json"