PT-2026-96160 · Drawio · Drawio

CVE-2026-76898

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions draw.io versions prior to 30.3.8
Description An issue exists where the application fails to properly block IPv6 Unique Local Addresses (ULA) because the check in Utils.sanitizeUrl() compares text prefixes fc00:: and fd00:: while the JDK returns expanded address forms. This allows the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, to bypass restrictions. An unauthenticated request to the /embed2.js?fetch= endpoint can cause EmbedServlet2.java to fetch internal IPv6 ULA resources and reflect the response to the requester, potentially disclosing cloud metadata credentials or data from other internal services. Additionally, Utils.validatedAddress() uses the same flawed check for the ProxyServlet path when ENABLE DRAWIO PROXY is set to 1.
Recommendations Update draw.io to version 30.3.8.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76898
GHSA-M3Q9-CWFQ-HCJC

Affected Products

Drawio