Executive brief
HyperDX, an observability platform, contains a security flaw that allows authorized team members to trick the server into making unauthorized requests to internal systems. By exploiting this, a user could access sensitive internal data, such as cloud provider credentials, database information, or private internal APIs that are not intended to be exposed. This could lead to a broader breach of the organization's internal infrastructure and cloud environment.
Technical details
HyperDX is vulnerable to Server-Side Request Forgery (SSRF) in two authenticated endpoints: `POST /webhooks/test` and `POST /clickhouse-proxy/test`. The root cause is insufficient validation of user-supplied host parameters, which allows requests to bypass hostname blacklists using direct IP literals (including RFC 1918, loopback, and link-local addresses). In the ClickHouse proxy endpoint, the vulnerability is further escalated from blind to reflected SSRF because the application returns the raw response body from the target in its error messages. An authenticated attacker can exploit this to probe internal services, access containerized sidecars, or retrieve sensitive credentials from cloud metadata endpoints (e.g., 169.254.169.254). The issue is mitigated in version 2.31.0 by implementing private IP blocking and redacting error responses, though DNS rebinding remains a known gap.
Affected products
- hyperdxio HyperDX before 2.31.0
Timeline
- 2026-06-01: disclosed: Originally reported via GHSA-fgcx-qxjr-wx26
- 2026-07-17: patched: Fix committed to main branch
- 2026-07-20: advisory: CVE-2026-63731 published
References
- https://github.com/hyperdxio/hyperdx/commit/1705b37ac68acc222cd038327ed79e167e256a1b
- https://github.com/hyperdxio/hyperdx/issues/2588
- https://github.com/hyperdxio/hyperdx/pull/2593
- https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0
- https://www.vulncheck.com/advisories/hyperdx-ssrf-via-clickhouse-proxy-test-endpoint