CVE-2026-71250: Firefly-Iii
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off by default) to configure a webhook targeting loopback services on the server.
Affected products
- Firefly-Iii Firefly-Iii: version 0 only
Published 2026-08-05. Last modified 2026-08-26.