top of page
perceptive_background_267k.jpg

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/…

Published:

31 August 2026 at 00:00:00

Alert date:

1 September 2026 at 01:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies

A server-side request forgery (SSRF) vulnerability was identified in hyperledger-firefly FireFly up to version 1.4.0. The vulnerability resides in the ValidateOptions function within the file internal/events/webhooks/webhooks.go, part of the Webhook Subscription component. An attacker can manipulate the 'url' argument to trigger SSRF attacks remotely. The exploit has been publicly disclosed and is available for use. The vulnerability allows remote exploitation without requiring local access. The vendor was notified prior to public disclosure but did not respond. No patch or mitigation from the vendor has been confirmed at the time of disclosure. This affects blockchain infrastructure tooling used in enterprise and decentralized application environments.

Technical details

Mitigation steps:

Affected products:

hyperledger-firefly FireFly up to 1.4.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page