CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73530

highCVSS 7.7covered by 1 sourcefirst seen 2026-08-13
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address :: which the kernel routes to loopback identically to 0.0.0.0. Attackers can submit requests or trigger 302 redirects to to bypass the private IP range and blocked hostname checks in is_private_ip(), reaching services bound to IPv6 loopback across the http.get, http.request, and http.batch` modules.

⚡ Watch CVE-2026-73530

Get an email if CVE-2026-73530 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73530

CVE.org record

Embed the live status

CVE-2026-73530 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73530 status](https://www.csirts.com/badge/CVE-2026-73530)](https://www.csirts.com/cve/CVE-2026-73530)