{"id":"CVE-2026-68558","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-68558","summary":"Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against…","details":"Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line check. The delivery path's fetchSafe guard already blocked the reported IPv4 destination, but its separate IPv4-only resolver and duplicated blocklist created inconsistent all-address-family enforcement and drift risk between input-time and connection-time validation. Version 9.74 makes server/lib/ssrfGuard.js resolve all addresses with `dns.lookup({ all: true })`, validate every result through the shared isIpBlocked logic, pin the connection, and block redirects. This issue is fixed in version 9.74.","published":"2026-08-19T19:22:18.718Z","modified":"2026-08-19T19:44:48.392Z","cvss":{"score":8.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/wekan/wekan/commit/ef845fe4a0adb82af436313310939cd48c0b1347","label":"wekan/wekan@ef845fe"},"references":[{"type":"WEB","url":"https://github.com/wekan/wekan/security/advisories/GHSA-66m2-4wfr-c45p"},{"type":"WEB","url":"https://github.com/wekan/wekan/commit/ef845fe4a0adb82af436313310939cd48c0b1347"},{"type":"WEB","url":"https://github.com/wekan/wekan/releases/tag/v9.74"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T19:44:48.392Z"}}