PatchSiren cyber security CVE debrief
CVE-2026-108602 Helicone CVE debrief
Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. This vulnerability can lead to potential blind POST requests to internal HTTPS services, exposure of internal services to authenticated users, and possible DNS rebinding attacks. Defenders should verify exposure of internal services, assess the impact of potential blind POST requests, and prioritize remediation.
- Vendor
- Helicone
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and security teams responsible for Helicone deployments, particularly those with internal services exposed to authenticated users, should assess exposure and potential impact. They should verify exposure of internal services, assess the impact of potential blind POST requests, and prioritize remediation. Security teams should also review webhook configurations and update to a fixed version if available.
Why it matters
Defenders should care about CVE-2026-108602 because it allows authenticated users to potentially reach internal services, leading to blind POST requests and possible exposure of sensitive information. Security teams should verify exposure, assess impact, and prioritize remediation.
- Potential blind POST requests to internal HTTPS services
- Exposure of internal services to authenticated users
- Possible DNS rebinding attacks
- Verification of webhook configurations and internal service exposure
Technical summary
The Helicone Jawn webhook sender is vulnerable to server-side request forgery, allowing authenticated organization users to reach internal services using hostnames resolving to private addresses. This can lead to blind POST requests to internal HTTPS services and potential exposure of sensitive information. Defenders should prioritize verifying exposure of internal services to authenticated users and assessing the impact of potential blind POST requests. The vulnerability is caused by the lack of proper validation of webhook configurations, allowing attackers to create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses.
Defensive priority
Defenders should prioritize verifying exposure of internal services to authenticated users and assessing the impact of potential blind POST requests.
Recommended defensive actions
- Verify exposure of internal services to authenticated users
- Assess the impact of potential blind POST requests
- Review webhook configurations for public hostnames resolving to private addresses
- Update to a fixed version if available
- Perform a thorough review of affected product deployments in managed environments
- Assign an owner for follow-up on remediation efforts
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability is described in the CVE record and NVD entry, with additional details provided in source references from GitHub and Vulncheck. The CVE record was published on 2026-10-10T20:16:32.650Z and has not been modified since then. The NVD entry provides a detailed assessment of the vulnerability. Additional information can be found in source references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Helicone/helicone
-
Source reference
Unverified legacy reference
URL: https://github.com/Helicone/helicone/blob/067d9290acb4f1fc9320e902fc67b4b399b50363/valhalla/jawn/src/controllers/public/webhookController.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/Helicone/helicone/blob/067d9290acb4f1fc9320e902fc67b4b399b50363/valhalla/jawn/src/lib/clients/webhookSender.ts
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/helicone-webhook-dns-ssrf
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/helicone-through-2025.08.21-1-ssrf-via-jawn-webhook-sender-dns-resolution
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.