CVE-2026-51583
High severity, CVSS 8.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
Published 2026-08-11. Last modified 2026-08-31.