Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups with public addresses and delivery lookups with private addresses to reach internal network resources.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups with public addresses and delivery lookups with private addresses to reach internal network resources. | |
| Title | Grav API Plugin before 1.0.16 SSRF via DNS Rebinding | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:08.721Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56708
No data.
Status : Received
Published: 2026-08-25T02:16:42.783
Modified: 2026-08-25T02:16:42.783
Link: CVE-2026-56708
No data.
OpenCVE Enrichment
Updated: 2026-08-25T03:30:05Z
Weaknesses