PT-2026-96187 · Homebox · Homebox

CVE-2026-55473

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HomeBox versions prior to 0.26.0
Description An authenticated user can trigger a Server-Side Request Forgery (SSRF) by submitting a generic:// notifier. The SSRF protections BlockBogonNets and BlockCloudMetadata in the file backend/internal/sys/validate/notifier url.go fail to inspect IPv4 destinations embedded within the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. On instances using NAT64/DNS64 egress, the gateway may translate these IPv6 destinations to localhost, cloud metadata, or other internal IPv4 hosts. This can be exploited via the endpoints 'POST /v1/notifiers' or 'POST /v1/notifiers/test'. The latter returns delivery results through Shoutrrr, which may disclose sensitive information such as temporary credentials.
Recommendations Update HomeBox to version 0.26.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55473
GHSA-R9PF-RG22-655M

Affected Products

Homebox