Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups with public addresses and delivery lookups with private addresses to reach internal network resources. | |
| Title | Grav API Plugin before 1.0.16 SSRF via DNS Rebinding | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T18:07:04.185Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56708
Updated: 2026-08-25T18:05:46.579Z
Status : Received
Published: 2026-08-25T02:16:42.783
Modified: 2026-08-25T18:17:56.467
Link: CVE-2026-56708
No data.
OpenCVE Enrichment
Updated: 2026-08-25T03:45:05Z