PT-2026-71153 · Microsoft · Ufo

CVE-2026-73297

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Microsoft UFO versions prior to 3.0.8
Description An issue exists where the is blocked ip function in ufo/utils/url security.py fails to block specific IPv6 prefixes, including NAT64 (64:ff9b::/96 and 64:ff9b:1::/48), 6to4 (2002::/16), and Teredo (2001::/32). Additionally, the system does not re-check embedded IPv4 destinations. This allows an unauthenticated remote attacker who can influence URLs processed by the validate url function to bypass the Server-Side Request Forgery (SSRF) guard—a security mechanism designed to prevent the server from making unauthorized requests—and access cloud metadata, internal services, or localhost.
Recommendations Update to version 3.0.8.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73297
GHSA-7HRG-R8XR-P8GR

Affected Products

Ufo