GHSA-35jm-rm2f-hpgjMediumCVSS 7.7

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that...

Published
August 13, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (1)

📋 Description

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks inis_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.

🔗 References (5)