CVE-2026-73530Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Eurico Nicacio { h3llh0und } 🏴@euriconicacio
    Disclosure

    CVE-2026-73530: reaching loopback through the IPv6 unspecified address Check the blog post: https://euriconicacio.github.io/blog/cve-2026-73530-reaching-loopback-through-the-ipv6-unspecified-address/ https://t.co/bEinKSoInM

    Post summary

    A tweet pointing to a blog post that announces CVE‑2026‑73530, describing an IPv6 related flaw allowing loopback access via the unspecified address, but provides no PoC, exploit code, patch details, or evidence of active exploitation.

    0003080
    279 followersView on X

Explore more