CVE-2026-104973: Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhooktask.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Plane versions prior to 1.4.0 are affected. The issue applies to webhook delivery, where the destination hostname can resolve differently when the delivery task sends the request.

2

What access does an attacker need to exploit this?

The vector requires network access and high privileges, as reflected by the supplied CVSS metrics. Exploitation does not require user interaction and has low attack complexity.

3

What is the practical impact of a successful exploit?

An attacker can use DNS rebinding to bypass the webhook SSRF protection and cause webhook delivery to reach an IP address that was not accepted during webhook creation. The supplied metrics indicate high confidentiality impact, low integrity impact, no availability impact, and scope change.

4

What should teams do if they cannot upgrade immediately?

The provided data identifies 1.4.0 as the fixed release but does not specify a workaround. Until upgrading, treat webhook destinations as sensitive and review configured webhook hostnames for destinations that could be controlled or DNS-rebound.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203