
CVE-2026-41455 WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without proto… https://www.cve.org/CVERecord?id=CVE-2026-41455
Post summary
CVE-2026-41455 exposes a server‑side request forgery in WeKan 8.34 and earlier, where the webhook URL field accepts any string without protocol validation.
