{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flyto2-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-73530"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flyto2 Core"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Flyto2"],"content_html":"\u003cp\u003eFlyto2 Core before version 2.28.0 contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthorized access to internal network services. The vulnerability originates in the is_private_ip() function, which fails to correctly sanitize or block the IPv6 loopback address notation \u003ccode\u003e::\u003c/code\u003e. Because the kernel interprets \u003ccode\u003e::\u003c/code\u003e identically to \u003ccode\u003e0.0.0.0\u003c/code\u003e (loopback), attackers can circumvent existing private IP range filters and hostname validation checks. This flaw affects multiple modules, specifically \u003ccode\u003ehttp.get\u003c/code\u003e, \u003ccode\u003ehttp.request\u003c/code\u003e, and \u003ccode\u003ehttp.batch\u003c/code\u003e. By manipulating these functions to target \u003ccode\u003e::\u003c/code\u003e, an attacker can force the application to make HTTP requests to internal services bound to the IPv6 loopback interface, potentially leading to unauthorized data exfiltration or service interaction. Organizations running Flyto2 Core must prioritize upgrading to version 2.28.0 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to interact with internal services that are otherwise protected by IP filtering or hostname validation, potentially leading to the leakage of internal application states, configuration data, or other sensitive information reachable via the loopback interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Flyto2 Core to version 2.28.0 or later immediately to patch the is_private_ip() filter logic.\u003c/li\u003e\n\u003cli\u003eReview web application logs for HTTP request patterns utilizing \u003ccode\u003e::\u003c/code\u003e or IPv6 loopback notations within URL parameters handled by the \u003ccode\u003ehttp\u003c/code\u003e modules.\u003c/li\u003e\n\u003cli\u003eImplement outbound network egress filtering at the host level to prevent the web application process from making unnecessary requests to local loopback addresses if not required by business logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T22:08:06Z","date_published":"2026-08-13T22:08:06Z","id":"https://feed.craftedsignal.io/briefs/2026-08-flyto2-ssrf/","summary":"Flyto2 Core versions prior to 2.28.0 are susceptible to SSRF via an IPv6 loopback bypass in the is_private_ip() function, enabling access to internal services.","title":"Flyto2 Core SSRF Vulnerability (CVE-2026-73530)","url":"https://feed.craftedsignal.io/briefs/2026-08-flyto2-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Flyto2 Core","version":"https://jsonfeed.org/version/1.1"}