PT-2026-82689 · Cc · Cc
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
CC: Tweaked versions prior to 1.120.0
Description
An issue exists in the Server-Side Request Forgery (SSRF) protection within the
AddressPredicate.java file. While the system blocks the RFC 6052 64:ff9b::/96 NAT64 prefix, it fails to block the RFC 8215 64:ff9b:1::/48 local-use prefix. On dual-stack servers utilizing RFC 8215 NAT64, an unauthenticated user capable of executing Lua code can utilize the http.request or http.websocket functions with an address under 64:ff9b:1::/48 to access loopback, RFC 1918, cloud metadata, or internal API endpoints. This occurs because the PrivatePattern.matches() function does not correctly classify the mapped IPv6 address as private.Recommendations
Update to version 1.120.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cc