<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hyperledger:firefly:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahyperledgerfirefly/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 01:01:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahyperledgerfirefly/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in Hyperledger FireFly Webhook Subscription Component</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-82957/</link><pubDate>Tue, 01 Sep 2026 01:01:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-82957/</guid><description>Hyperledger FireFly versions 1.4.0 and earlier contain an SSRF vulnerability in the Webhook Subscription component, allowing unauthenticated remote attackers to perform unauthorized requests via manipulation of the URL argument.</description><content:encoded><![CDATA[<p>Hyperledger FireFly versions up to and including 1.4.0 are vulnerable to a Server-Side Request Forgery (SSRF) flaw located in the ValidateOptions function within internal/events/webhooks/webhooks.go. This component, responsible for handling Webhook Subscriptions, fails to properly validate the 'url' parameter provided during configuration or execution. An unauthenticated remote attacker can exploit this flaw by supplying a crafted URL to the webhook service, forcing the application to perform requests on behalf of the server. This can lead to unauthorized access to internal services, metadata endpoints, or external resources. Public exploit code is currently available, and the vendor has not provided a patch or formal response to the disclosure, making this a high-priority risk for organizations running Hyperledger FireFly instances.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to bypass perimeter security to scan and interact with internal network resources, potentially leading to unauthorized data exfiltration or access to sensitive internal APIs. As the vulnerability is remote and requires no authentication, instances exposed to the internet are at immediate risk of exploitation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize network-level segmentation to restrict the ability of the Hyperledger FireFly service to make outbound connections to internal and private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Monitor webserver logs for unexpected requests to internal infrastructure or unusual URL patterns targeting administrative interfaces. Ensure that the FireFly service runs with the least privilege necessary to minimize the impact if an SSRF condition is successfully triggered.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>