Medium severity6.5NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104458
CVE-2026-104458
Description
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible IPv6 addresses. Attackers can send a crafted Signature keyId to the public actor inbox route to reach cloud metadata, loopback services, or internal hosts.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.