PT-2026-93226 · Unknown · Home Assistant
CVE-2026-91129
·
Published
2026-08-12
·
Updated
2026-09-25
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions prior to 2026.2.3
Description
The IPP integration automatically processes unauthenticated
ipp. tcp.local mDNS announcements. In the homeassistant/components/ipp/config flow.py file, the async step zeroconf function passes attacker-controlled host, port, and base path values to validate input for printer metadata retrieval. Since the shared HTTP client follows cross-origin redirects without blocking loopback targets, a local-network attacker can redirect requests to 127.0.0.1 or other internal services without user interaction or prior configuration. This leads to a Server-Side Request Forgery (SSRF), where the server is tricked into making unauthorized requests to internal resources.Recommendations
Update to version 2026.2.3.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Assistant