Server-Side Request Forgery (SSRF) in ip-address - #VU146516
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass network trust boundaries and conduct server-side request forgery.
The vulnerability exists due to improper address classification in the Address6 classifier when processing NAT64 local-use IPv6 addresses in the 64:ff9b:1::/48 range. A remote attacker can supply a specially crafted address that is classified as a global address to bypass network trust boundaries and conduct server-side request forgery.
Exploitation requires the server network to run a NAT64 translator on a prefix inside 64:ff9b:1::/48, and the attacker must know or guess the deployed prefix length.