1. GitHub Security Alert: Merchant Webhook SSRF Vulnerability Exposes Internal Server Port Scanning
A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in a GitHub repository's webhook system. The flaw allows a merchant to specify a webhook URL pointing to `127.0.0.1` or other loopback addresses, which could force the application's API to perform port scans against its own server instance....