CVE-2026-73530

Summary

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks inis_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.

Affected Software

VendorProductVersion RangeStatus
flytohubflyto-core0 < 2.28.0affected

Weaknesses

  • CWE-918: Server-Side Request Forgery (SSRF)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References