CVE-2026-72761
Description
The webhook URL validator in website/notifications/webhooks.py uses ip.is_global to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 64:ff9b::/96, 6to4 2002::/16, Teredo 2001:0000::/32) are classified as globally routable by IANA, so is_global returns True even when the embedded IPv4 targets a private, loopback, or cloud metadata destination. An attacker can register a webhook pointing at a hostname that resolves to a transition address to bypass the SSRF guard and exfiltrate vulnerability data to an internal endpoint.
The vulnerability was introduced on a non-release version. The fix was already done on HEAD. It only affects
organisation running the HEAD.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: HEAD
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.