Skip to content

MCPA-2026-0013

highssrfCVSS 7.1

Flyto2 Core SSRF guard bypass via IPv6 transition addresses (CVE-2026-55787)

flyto-core before 2.26.3 validates outbound URLs in validate_url_ssrf but does not account for IPv6 transition addressing (IPv4-mapped, 6to4, NAT64), so requests that appear to target public IPv6 addresses can be routed to internal IPv4 hosts, bypassing the SSRF guard. Fixed in 2.26.3.

Affected packages

EcosystemPackageAffected versions
pypiflyto-core
>= 0, < 2.26.3

Identifiers

CVE-2026-55787GHSA-794r-5rp2-fpg8PYSEC-2026-2481CWE-918

References

Timeline

  • Published: 2026-07-06

← All advisories