CVE-2026-108602
Deferred Deferred - Pending Action

Helicone SSRF via Jawn Webhook Sender

Vulnerability report for CVE-2026-108602, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Helicone helicone 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Helicone's Jawn webhook sender component. Authenticated organization users can create webhooks with public hostnames that resolve to private or loopback addresses (like 127.0.0.1 or 10.x.x.x). The system checks the hostname string but not the resolved IP, allowing blind POST requests to internal HTTPS services.

Detection Guidance

To detect this SSRF vulnerability in Helicone, monitor outbound HTTPS connections from the Jawn service to internal or loopback addresses. Check logs for POST requests to private IPs like 127.0.0.1 or 10.x.x.x. Use network monitoring tools like tcpdump or Wireshark to capture traffic from the Jawn container or host. Inspect webhook configurations in Helicone's database for suspicious destination URLs.

Impact Analysis

An attacker with organization access could send requests to internal services reachable by the Jawn server. This could lead to unauthorized access to internal APIs, data exfiltration, or service disruption. The impact depends on which internal services are accessible.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to internal systems, potentially exposing sensitive data. Organizations using Helicone must address this to maintain SOC 2, GDPR, or other regulatory compliance standards.

Mitigation Strategies

Upgrade Helicone to a patched version beyond v2025.08.21-1. Disable webhook creation for untrusted users. Implement network policies to block outbound connections from Jawn to private IP ranges. Add IP validation during webhook destination checks instead of relying on hostname strings alone.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108602. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart