PT-2026-65891 · Unknown · Flyto2 Core

CVE-2026-67424

·

Published

2026-07-29

·

Updated

2026-08-04

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flyto2 Core versions prior to 2.26.7
Description The HTTP modules http.get, http.request, and http.batch validate only the initial URL. When allow redirects is set to True, the system follows redirects without per-hop Location revalidation. This allows a public URL to redirect into internal address space, enabling the retrieval of internal response bodies.
Recommendations Update to version 2.26.7.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67424
GHSA-C9HR-64H3-GXPC
PYSEC-2026-3569

Affected Products

Flyto2 Core