HIGHVulnerability

CVE-2026-71272

Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather than the already-validated IP address.

Properties

severity
HIGH
score
8.5
cve_id
CVE-2026-71272
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
published_at
2026-08-05T13:24:51.573
last_modified
2026-08-26T17:13:24.800

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71272 — Ninja Signal Threat Intelligence | Ninja Signal