Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could end up in retrieving confidential metadata of cloud/hosting providers. The existing check is now extended and is applied when configuring webhooks as well as triggering webhook jobs. This vulnerability is fixed in 7.0.1 and 6.5.4.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:* cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:* |
Fri, 10 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zammad
Zammad zammad |
|
| Vendors & Products |
Zammad
Zammad zammad |
Wed, 08 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could end up in retrieving confidential metadata of cloud/hosting providers. The existing check is now extended and is applied when configuring webhooks as well as triggering webhook jobs. This vulnerability is fixed in 7.0.1 and 6.5.4. | |
| Title | Zammad has a Server-side request forgery (SSRF) via webhooks | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-08T18:02:16.224Z
Updated: 2026-04-10T20:38:50.653Z
Reserved: 2026-03-30T18:41:20.753Z
Link: CVE-2026-34719
Updated: 2026-04-10T20:38:40.833Z
Status : Analyzed
Published: 2026-04-08T19:25:22.003
Modified: 2026-04-17T15:27:09.523
Link: CVE-2026-34719
No data.