Multiple security vulnerabilities have been identified in unleash-server, a package that allows for the creation of serverless applications. The overall risk and impact are significant, as these vulnerabilities can lead to denial-of-service (DoS) attacks, server-side request forgery (SSRF), and link-injection via unrestricted username. Affected version range is not explicitly stated.
CVE-2026-63462 (CVSS 7.5 — High): An unauthenticated single-request DoS attack can be performed via an OpenAPI validation error formatter in unleash-server.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in unleash-server, a package that allows for the creation of serverless applications. The overall risk and impact are significant, as these vulnerabilities can lead to denial-of-service (DoS) attacks, server-side request forgery (SSRF), and link-injection via unrestricted username. Affected version range is not explicitly stated.
CVE-2026-63462 (CVSS 7.5 — High): An unauthenticated single-request DoS attack can be performed via an OpenAPI validation error formatter in unleash-server.[emaillocker id="1283"]
CVE-2026-63004: An addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services and cloud metadata exfiltration of configured request headers.
CVE-2026-63466 (CVSS 7.5 — High): A global Mustache.escape override disables HTML escaping process-wide, enabling link-injection via unrestricted username in unleash-server.
These vulnerabilities collectively present a significant risk to administrators who have not applied the latest patches.
We recommend you to update unleash-server to version 7.5.2 or 7.6.5 or 8.0.2
The following reports contain further technical details:
[/emaillocker]