CVE-2026-104973: Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhooktask.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are affected?
Plane versions prior to 1.4.0 are affected. The issue applies to webhook delivery, where the destination hostname can resolve differently when the delivery task sends the request.
What access does an attacker need to exploit this?
The vector requires network access and high privileges, as reflected by the supplied CVSS metrics. Exploitation does not require user interaction and has low attack complexity.
What is the practical impact of a successful exploit?
An attacker can use DNS rebinding to bypass the webhook SSRF protection and cause webhook delivery to reach an IP address that was not accepted during webhook creation. The supplied metrics indicate high confidentiality impact, low integrity impact, no availability impact, and scope change.
What should teams do if they cannot upgrade immediately?
The provided data identifies 1.4.0 as the fixed release but does not specify a workaround. Until upgrading, treat webhook destinations as sensitive and review configured webhook hostnames for destinations that could be controlled or DNS-rebound.