PT-2026-71153 · Microsoft · Ufo
CVE-2026-73297
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Microsoft UFO versions prior to 3.0.8
Description
An issue exists where the
is blocked ip function in ufo/utils/url security.py fails to block specific IPv6 prefixes, including NAT64 (64:ff9b::/96 and 64:ff9b:1::/48), 6to4 (2002::/16), and Teredo (2001::/32). Additionally, the system does not re-check embedded IPv4 destinations. This allows an unauthenticated remote attacker who can influence URLs processed by the validate url function to bypass the Server-Side Request Forgery (SSRF) guard—a security mechanism designed to prevent the server from making unauthorized requests—and access cloud metadata, internal services, or localhost.Recommendations
Update to version 3.0.8.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ufo