Server-Side Request Forgery (SSRF) in Mautic - CVE-2025-9821
Published: May 25, 2026
Mautic
Detailed vulnerability description
The vulnerability allows a remote user to interact with internal services and disclose partial response data.
The vulnerability exists due to server-side request forgery (SSRF) in the webhook function when sending webhooks to an unvalidated destination. A remote privileged user can configure a webhook destination to access internal services and disclose partial response data.
If the user can view webhook logs, partial request responses are disclosed.