MCPA-2026-0013
highssrfCVSS 7.1
Flyto2 Core SSRF guard bypass via IPv6 transition addresses (CVE-2026-55787)
flyto-core before 2.26.3 validates outbound URLs in validate_url_ssrf but does not account for IPv6 transition addressing (IPv4-mapped, 6to4, NAT64), so requests that appear to target public IPv6 addresses can be routed to internal IPv4 hosts, bypassing the SSRF guard. Fixed in 2.26.3.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | flyto-core | >= 0, < 2.26.3 |
Identifiers
CVE-2026-55787GHSA-794r-5rp2-fpg8PYSEC-2026-2481CWE-918
References
- advisory https://github.com/advisories/GHSA-794r-5rp2-fpg8
- web https://osv.dev/vulnerability/PYSEC-2026-2481
- web https://nvd.nist.gov/vuln/detail/CVE-2026-55787
Timeline
- Published: 2026-07-06