What is CVE-2026-71250?
CVE-2026-71250 is a flaw in Firefly III's webhook URL validator that allows authenticated users with webhooks enabled to bypass IP filtering and target any address in the 127.0.0.0/8 range. Applying the vendor-supplied security update is recommended to mitigate this Server-Side Request Forgery (SSRF) risk.
Azərbaycanca: CVE-2026-71250 Firefly III tətbiqində vebhook URL validatorunda aşkarlanmış bir boşluqdur. Autentifikasiya olunmuş istifadəçilər (vebhook funksiyası standart olaraq qapalıdır) `127.0.0.0/8` diapazonuna daxil olan hər hansı bir ünvana sorğu göndərə bilir. Bu zəifliyin qarşısını almaq üçün Firefly III tərtibatçıları tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Does exploiting CVE-2026-71250 require authentication?
Yes, it requires an authenticated user and the webhooks feature must be enabled (which is disabled by default).
What type of vulnerability is CVE-2026-71250?
It is a flaw that poses a Server-Side Request Forgery (SSRF) risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.