Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The webhook monitor defaults to binding the HTTP server to 0.0.0.0, which exposes the listener on all network interfaces unless the operator explicitly overrides webhookHost. Although the endpoint uses HMAC verification and backend-origin checks, broad exposure still increases attack surface for brute-force attempts, malformed-request abuse, and accidental internet exposure in self-hosted deployments.
