CVE-2026-63730

medium

Description

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.

References

https://www.vulncheck.com/advisories/hyperdx-ssrf-via-webhook-test-endpoint

https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0

https://github.com/hyperdxio/hyperdx/pull/2593

https://github.com/hyperdxio/hyperdx/issues/2588

https://github.com/hyperdxio/hyperdx/commit/1705b37ac68acc222cd038327ed79e167e256a1b

Details

Source: Mitre, NVD

Published: 2026-07-20

Updated: 2026-07-23

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00233