PT-2026-96798 · Cloudreve · Cloudreve
CVE-2026-79913
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cloudreve versions prior to 4.18.0
Description
An authenticated user with remote-download access can perform a Server-Side Request Forgery (SSRF) by providing a specially crafted
SrcUri through the RemoteDownloadTask.createDownloadTask function. The SSRF guard ValidateExternalURL in pkg/request/ssrf.go uses the checkIP() function, which fails to decode certain IPv4-in-IPv6 transition forms, including NAT64, IPv4-compatible, and 6to4 addresses. Because these wrappers are classified as public global IPv6 addresses, an attacker can bypass the guard to access internal loopback, private, link-local, or cloud metadata IPv4 addresses (such as 169.254.169.254). This can lead to the exposure of internal service responses and the theft of cloud instance IAM role credentials.Recommendations
Update Cloudreve to version 4.18.0 or later.
As a temporary mitigation, restrict the use of the
SrcUri parameter in the remote-download workflow to trusted domains only.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudreve