Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35jm-rm2f-hpgj

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 7.7

Описание

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks inis_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks inis_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918