CVE-2025-9821

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.
Configurations

No configuration.

History

03 Sep 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-03 10:15

Updated : 2025-09-04 15:36


NVD link : CVE-2025-9821

Mitre link : CVE-2025-9821

CVE.ORG link : CVE-2025-9821


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)