PT-2026-96187 · Homebox · Homebox
CVE-2026-55473
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HomeBox versions prior to 0.26.0
Description
An authenticated user can trigger a Server-Side Request Forgery (SSRF) by submitting a
generic:// notifier. The SSRF protections BlockBogonNets and BlockCloudMetadata in the file backend/internal/sys/validate/notifier url.go fail to inspect IPv4 destinations embedded within the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. On instances using NAT64/DNS64 egress, the gateway may translate these IPv6 destinations to localhost, cloud metadata, or other internal IPv4 hosts. This can be exploited via the endpoints 'POST /v1/notifiers' or 'POST /v1/notifiers/test'. The latter returns delivery results through Shoutrrr, which may disclose sensitive information such as temporary credentials.Recommendations
Update HomeBox to version 0.26.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homebox