PT-2026-96160 · Drawio · Drawio
CVE-2026-76898
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
draw.io versions prior to 30.3.8
Description
An issue exists where the application fails to properly block IPv6 Unique Local Addresses (ULA) because the check in
Utils.sanitizeUrl() compares text prefixes fc00:: and fd00:: while the JDK returns expanded address forms. This allows the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, to bypass restrictions. An unauthenticated request to the /embed2.js?fetch= endpoint can cause EmbedServlet2.java to fetch internal IPv6 ULA resources and reflect the response to the requester, potentially disclosing cloud metadata credentials or data from other internal services. Additionally, Utils.validatedAddress() uses the same flawed check for the ProxyServlet path when ENABLE DRAWIO PROXY is set to 1.Recommendations
Update draw.io to version 30.3.8.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drawio