Server-Side Request Forgery (SSRF) in snipe-it - #VU145074
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to access internal services and disclose sensitive information via server-side request forgery.
The vulnerability exists due to improper restriction of rendered transition IPv6 addresses in ExternalUrl validation rule in app/Rules/ExternalUrl.php when validating webhook URLs or resolved AAAA records. A remote privileged user can supply a specially crafted webhook URL containing an IPv6 transition address or a hostname resolving to one to access internal services and disclose sensitive information via server-side request forgery.
Exploitation is possible on NAT64-, 6to4-, or Teredo-enabled hosts and can target cloud instance metadata endpoints such as 169.254.169.254.