MEDIUM 6.3 NVD
CVE-2026-73530
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs u
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.
References
- https://github.com/flytohub/flyto-core/releases/tag/v2.28.0
- https://github.com/flytohub/flyto-core/security/advisories/GHSA-gc4h-hj7x-gp5p
- https://www.vulncheck.com/advisories/flyto2-core-ssrf-guard-bypass-via-is-private-ip
- https://github.com/flytohub/flyto-core/security/advisories/GHSA-gc4h-hj7x-gp5p
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10812 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.