PT-2026-93226 · Unknown · Home Assistant

CVE-2026-91129

·

Published

2026-08-12

·

Updated

2026-09-25

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.2.3
Description The IPP integration automatically processes unauthenticated ipp. tcp.local mDNS announcements. In the homeassistant/components/ipp/config flow.py file, the async step zeroconf function passes attacker-controlled host, port, and base path values to validate input for printer metadata retrieval. Since the shared HTTP client follows cross-origin redirects without blocking loopback targets, a local-network attacker can redirect requests to 127.0.0.1 or other internal services without user interaction or prior configuration. This leads to a Server-Side Request Forgery (SSRF), where the server is tricked into making unauthorized requests to internal resources.
Recommendations Update to version 2026.2.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91129
GHSA-4GHV-53CQ-7WP3
ZDI-26-562

Affected Products

Home Assistant