CVE-2026-33975Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g., ::ffff:169.254.169.254 becomes ::ffff:a9fe:a9fe), but the isPrivateIp utility only recognizes the dotted-decimal notation. As a result, the hex form passes the SSRF check unchecked. Additionally, the socket lookup validation event does not fire for IP literal addresses, bypassing the second validation layer. An authenticated user can reach any internal IP, including cloud metadata endpoints, to exfiltrate credentials such as IAM keys.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Technical Details · 2026-05-05: 305-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33975 SSRF Protection Bypass in Twenty CRM via IPv4-Mapped IPv6 Addresses https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33975

    Post summary

    The text announces CVE‑2026‑33975, detailing an SSRF bypass in Twenty CRM that exploits IPv4‑mapped IPv6 addresses, but no PoC, exploit code, active exploitation, or patch information is provided.

    0000049
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33975 Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypass… https://www.cve.org/CVERecord?id=CVE-2026-33975 ----- Traducción: CVE-2026-33975 Twe… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33975, describing an SSRF bypass vulnerability in older releases of the open‑source CRM Twenty, and directs readers to the official CVE record.

    0000043
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33975 Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypass… https://www.cve.org/CVERecord?id=CVE-2026-33975

    Post summary

    An SSRF bypass vulnerability (CVE-2026-33975) has been disclosed for the open‑source CRM Twenty, affecting versions 1.18.0 and earlier, with no exploit code or patch noted.

    00000171
    57.4K followersView on X

Explore more