---
id: CVE-2026-108602
title: >-
  Helicone through v2025.08.21-1 contains a server-side request forgery
  vulnerability in the Jawn webhook sender that allows authenticated
  organization users to reach internal services by using hostnames resolving to
  private addresses
summary: >-
  Helicone through v2025.08.21-1 contains a server-side request forgery
  vulnerability in the Jawn webhook sender that allows authenticated
  organization users to reach internal services by using hostnames resolving to
  private addresses. Att…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-918
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T20:16:32.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108602'
references:
  - url: 'https://github.com/Helicone/helicone'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Helicone/helicone/blob/067d9290acb4f1fc9320e902fc67b4b399b50363/valhalla/jawn/src/controllers/public/webhookController.ts#L64-L85
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Helicone/helicone/blob/067d9290acb4f1fc9320e902fc67b4b399b50363/valhalla/jawn/src/lib/clients/webhookSender.ts#L11-L76
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@haind/helicone-webhook-dns-ssrf'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/helicone-through-2025.08.21-1-ssrf-via-jawn-webhook-sender-dns-resolution
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T20:31:30.634Z'
---

## Overview

Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
