Junglewise Threat Intelligence

CVE-2026-100863: Heym server-side request forgery in image fetching and IPv6 validation

CVE-2026-100863 · Severity: medium · CVSS 5 · Published 2026-09-27

Technologies: Heym. Vendors: Heym.

Executive brief

Heym is a workflow automation platform that processes user-supplied URLs and network requests. The vulnerability allows attackers with API or webhook access to redirect image fetches to internal servers, loopback addresses, or cloud metadata endpoints through two flaws: unguarded HTTP image downloads and incomplete IPv6 address validation. This could expose internal services, cloud credentials, or private data.

Technical details

The image-edit loader (_load_image_bytes) fetches caller-controlled HTTP/HTTPS URLs using bare httpx.get with only scheme validation, bypassing the egress-pinning HTTP client used for HTTP nodes. Additionally, _is_public_address fails to validate IPv6 transition forms (NAT64 64:ff9b::/96, IPv4-compatible ::x.x.x.x, 6to4 2002::/16), allowing embedded loopback or RFC1918 addresses to pass both initial validation and dial-time IP pinning. Version 0.0.91 routes image loads through the guarded HTTP client with full address validation and explicit rejection of transition prefixes.

Affected products

  • Heym Heym 0.0.90 and earlier

Timeline

  • 2026-08-15: disclosed: GitHub Security Advisory GHSA-6rph-qqcv-jqh4 published
  • 2026-09-27: patched: Version 0.0.91 released with fixes to ssrf_guard.py

References

Related threats