High severity7.7NVD Advisory· Published Aug 13, 2026
CVE-2026-73530
CVE-2026-73530
Description
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks in is_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.
Affected products
1- Range: <2.28.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.