PT-2026-82689 · Cc · Cc

·

CVE-2026-55758

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions CC: Tweaked versions prior to 1.120.0
Description An issue exists in the Server-Side Request Forgery (SSRF) protection within the AddressPredicate.java file. While the system blocks the RFC 6052 64:ff9b::/96 NAT64 prefix, it fails to block the RFC 8215 64:ff9b:1::/48 local-use prefix. On dual-stack servers utilizing RFC 8215 NAT64, an unauthenticated user capable of executing Lua code can utilize the http.request or http.websocket functions with an address under 64:ff9b:1::/48 to access loopback, RFC 1918, cloud metadata, or internal API endpoints. This occurs because the PrivatePattern.matches() function does not correctly classify the mapped IPv6 address as private.
Recommendations Update to version 1.120.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55758
GHSA-2RRX-MCH2-76CP

Affected Products

Cc