CVE-2026-104973
Deferred Deferred - Pending Action

Plane Project Management Tool SSRF via DNS Rebinding

Vulnerability report for CVE-2026-104973, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104973 is a Server-Side Request Forgery (SSRF) vulnerability in the Plane project management tool. It allows attackers to bypass SSRF protections by exploiting DNS rebinding. The issue occurs because webhook IP addresses were validated only at creation time, but the delivery task performed separate DNS resolution without re-validation. Attackers could initially pass validation with a public IP, then change the DNS record to resolve to an internal IP when the webhook is triggered, enabling access to internal networks or cloud metadata endpoints.

Detection Guidance

To detect this vulnerability, monitor webhook logs for unexpected internal IP connections or DNS rebinding attempts. Check for logs indicating connections to internal addresses like 169.254.169.254 or other private ranges. Review webhook delivery tasks for unresolved DNS resolutions or redirects to disallowed domains.

Impact Analysis

This vulnerability could allow attackers to access internal network resources, steal cloud credentials (e.g., AWS metadata endpoint 169.254.169.254), or expose sensitive responses. It may also enable privilege escalation if internal services are compromised. The impact includes high confidentiality loss due to potential exposure of sensitive data.

Compliance Impact

This vulnerability enables attackers to bypass SSRF protections via DNS rebinding, potentially exposing sensitive internal network data or cloud credentials. Such unauthorized access could lead to violations of data protection requirements under GDPR (e.g., unauthorized data exfiltration) or HIPAA (e.g., exposure of protected health information). The lack of proper IP validation during webhook delivery increases the risk of non-compliance with these standards.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to apply the SSRF protection fixes. Ensure the new url_security.py utility is active and validating all webhook deliveries. Disable environment proxies that could bypass IP pinning and review webhook logs for any suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104973. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart