Incomplete List of Disallowed Inputs in NukeViet - #VU153179
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause the server to issue requests to internal hosts and disclose limited internal binary files.
The vulnerability exists due to incomplete validation of IPv4-mapped IPv6 addresses in the URL-based file import feature when submitting a hostname whose AAAA record resolves to a mapped internal address. A remote privileged user can submit a crafted hostname to cause the server to issue requests to internal hosts and disclose limited internal binary files.
Exploitation reaches internal IPv4 services only on operating systems that map IPv4-mapped IPv6 addresses to IPv4 endpoints; persisted responses must be recognized as allowed binary file types.