CVE-2026-63004

Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to Addon.fetchRetry in src/lib/addons/addon.ts without restricting loopback, link-local, private, or cloud metadata addresses. An authenticated actor with the root CREATE_ADDON or UPDATE_ADDON permission can cause the server to send requests from inside its network boundary, use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an attacker-observed host, and deliver the feature-event JSON body to internal services. This issue is fixed in versions 7.5.2, 7.6.5, and 8.0.2.


We have discovered 778 live websites that are affected by CVE-2026-63004.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains778 live websites (100% of Gitea install base)
Vulnerable Versions
  • from 0 through 7.5.2
  • from 7.6 through 7.6.5
  • from 8 through 8.0.2
Vulnerable Versions Count66 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Aug 21, 2026
  • Updated - Aug 21, 2026

Website Distribution by Country

Number of websites using CVE-2026-63004
United States192 websites



Germany206 websites
France104 websites
Russia47 websites
Singapore42 websites
China24 websites
Czech Republic18 websites
Netherlands16 websites
GB15 websites
Canada10 websites

Website Distribution by TLD

Number of websites using CVE-2026-63004
.com192 websites
.net78 websites
.org77 websites
.de77 websites
.ru32 websites
.fr27 websites
.eu16 websites
.nl14 websites
.io12 websites
.cz11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-63004

Top websites that are affected by CVE-2026-63004. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***,***
***.*************.org United States***,***
*****.**********.eu Germany***,***
***.*******.net United States***,***
******************.com United States*,***,***
**********.es France*,***,***
****.********.ch Switzerland*,***,***
***.*******.fi Finland*,***,***
***.*********.rip Germany*,***,***
***.************.com France*,***,***
See full domain list

FAQ

CVE-2026-63004 is Server-Side Request Forgery (SSRF) in Gitea
A total of 778 websites have been identified as vulnerable to CVE-2026-63004, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2026-63004 vulnerability.
Gitea versions up to 8.0.2 are vulnerable to CVE-2026-63004.
CVE-2026-63004 is resolved in version 8.0.2 of Gitea.