A vulnerability marked as critical has been reported in Firefly III. The impacted element is the function gethostbyname of the file IsValidWebhookUrl.php of the component Webhook URL Validator. This manipulation causes server-side request forgery.

This vulnerability appears as CVE-2026-71250. The attack may be initiated remotely. There is no available exploit.