Skip to content
Threat Feed

Tag

Ipv6

6 briefs RSS
high advisory

Gotenberg SSRF via IPv6 Address Confusion (CVE-2026-45741)

Gotenberg's `IsPublicIP` function incorrectly classifies IPv6 6to4, NAT64, and deprecated site-local addresses as public IPs, enabling an unauthenticated attacker to reach internal destinations such as cloud metadata services.

gotenberg/gotenberg/v8 ssrf gotenberg ipv6 cve-2026-45741
2r 1t 1c
medium advisory

CVE-2026-46172 Vulnerability in IPv6 xfrm6_rcv_encap()

CVE-2026-46172 is a vulnerability related to ipv6: xfrm6: release dst on error in xfrm6_rcv_encap(), potentially leading to a denial-of-service condition.

ipv6 denial-of-service CVE-2026-46172
2r 1t 1c
medium advisory

CVE-2026-46099: IPv6 NOREF DST Use Vulnerability in seg6 and rpl lwtunnels

CVE-2026-46099 describes a vulnerability in the IPv6 network stack related to NOREF dst use in seg6 and rpl lwtunnels, requiring a security update to address potential exploitation.

ipv6 network denial-of-service information-disclosure
2r 1c
medium advisory

Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)

Better Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.

better-auth +4 rate-limiting authentication ipv6 cve-2026-45364
2r
high advisory

dssrf SSRF Protection Bypass via IPv6 Addresses

A vulnerability in the dssrf npm package allows attackers to bypass SSRF protections by using specially crafted IPv6 addresses, despite documentation claiming IPv6 is disabled, which can lead to internal resource access or other malicious activities.

dssrf ssrf vulnerability ipv6 defense-evasion
2r 12i
high advisory

link-preview-js vulnerable to IPv6 and internal loopback attacks

link-preview-js versions 4.0.0 and earlier are vulnerable to IPv6 and internal loopback attacks, allowing potential internal data leaks by resolving addresses to internal IPs; patched in version 4.0.1.

link-preview-js loopback ipv6 dns internal-ip
3r 1t