PT-2026-96798 · Cloudreve · Cloudreve

CVE-2026-79913

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cloudreve versions prior to 4.18.0
Description An authenticated user with remote-download access can perform a Server-Side Request Forgery (SSRF) by providing a specially crafted SrcUri through the RemoteDownloadTask.createDownloadTask function. The SSRF guard ValidateExternalURL in pkg/request/ssrf.go uses the checkIP() function, which fails to decode certain IPv4-in-IPv6 transition forms, including NAT64, IPv4-compatible, and 6to4 addresses. Because these wrappers are classified as public global IPv6 addresses, an attacker can bypass the guard to access internal loopback, private, link-local, or cloud metadata IPv4 addresses (such as 169.254.169.254). This can lead to the exposure of internal service responses and the theft of cloud instance IAM role credentials.
Recommendations Update Cloudreve to version 4.18.0 or later. As a temporary mitigation, restrict the use of the SrcUri parameter in the remote-download workflow to trusted domains only.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79913
GHSA-JVH5-97XG-V99F

Affected Products

Cloudreve