Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Teams, Datadog, and New Relic integrations to Addon.fetchRetry in src/lib/addons/addon.ts without restricting loopback, link-local, private, or cloud metadata addresses. An authenticated actor with the root CREATE_ADDON or UPDATE_ADDON permission can cause the server to send requests from inside its network boundary, use integration event status as a blind probing oracle, forward Authorization, customHeaders, or DD-API-KEY values to an attacker-observed host, and deliver the feature-event JSON body to internal services. This issue is fixed in versions 7.5.2, 7.6.5, and 8.0.2.
We have discovered 778 live websites that are affected by CVE-2026-63004.
| 192 websites | |
| 206 websites | |
| 104 websites | |
| 47 websites | |
| 42 websites | |
| 24 websites | |
| 18 websites | |
| 16 websites | |
| 15 websites | |
| 10 websites |
| .com | 192 websites |
| .net | 78 websites |
| .org | 77 websites |
| .de | 77 websites |
| .ru | 32 websites |
| .fr | 27 websites |
| .eu | 16 websites |
| .nl | 14 websites |
| .io | 12 websites |
| .cz | 11 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.********.com | ***,*** | ||
| ***.*************.org | ***,*** | ||
| *****.**********.eu | ***,*** | ||
| ***.*******.net | ***,*** | ||
| ******************.com | *,***,*** | ||
| **********.es | *,***,*** | ||
| ****.********.ch | *,***,*** | ||
| ***.*******.fi | *,***,*** | ||
| ***.*********.rip | *,***,*** | ||
| ***.************.com | *,***,*** |
FAQ