Sceawere

Vulnerability Detail

CVE-2026-104458UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki SSRF Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible IPv6 addresses. Attackers can send a crafted Signature keyId to the public actor inbox route to reach cloud metadata, loopback services, or internal hosts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-02T12:17:17.813Z",
  "pubdate": "2026-10-02T12:17:17.813Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are affected by a Server-Side Request Forgery (SSRF) vulnerability located within the validateKeyIdUrl() function.\nThis vulnerability enables unauthenticated, remote attackers to bypass internal SSRF validation mechanisms. By utilizing specific IPv6 transition and translation addresses—such as 6to4, NAT64, or IPv4-compatible IPv6 formats—attackers can trick the application into making requests to restricted network spaces.\nThe impact of successful exploitation is significant: it allows unauthorized access to loopback services, internal network hosts, and sensitive cloud metadata services (such as the AWS Instance Metadata Service).\nBecause this vulnerability can be triggered via unauthenticated requests to the public actor inbox route by sending a crafted Signature keyId, it presents a severe security risk to organizations hosting vulnerable YesWiki instances. This security flaw potentially leads to sensitive information disclosure, lateral movement within the hosting infrastructure, or internal service compromise, all without requiring any valid user credentials or prior authentication on the target platform.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient input validation and address parsing logic within the validateKeyIdUrl() function of YesWiki. The function is designed to validate external URLs provided in the Signature keyId parameter of incoming ActivityPub-style requests to the public actor inbox. This validation is intended to prevent SSRF by blocking requests to loopback addresses (like 127.0.0.1 or ::1) and private IP ranges (RFC 1918). However, the implementation fails to account for alternative IPv6 addressing representations that resolve to or wrap IPv4 addresses. Specifically, the parser does not adequately normalize or restrict 6to4 addresses (which use the prefix 2002::/16), NAT64 addresses (often using the prefix 64:ff9b::/96), or IPv4-compatible IPv6 addresses (which encode an IPv4 address in the low-order 32 bits of an IPv6 address, such as ::ffff:0:0/96 or ::/96). When an unauthenticated attacker sends a crafted Signature keyId containing a URL with one of these specialized IPv6 formats, the validateKeyIdUrl() function evaluates the address. Because the validation logic does not recognize these transition formats as pointing to local or private scopes, the request passes the SSRF guard. The application's HTTP client subsequently resolves and connects to the specified destination, executing the unauthorized request on behalf of the attacker.\nThe attack flow proceeds systematically as follows: First, the attacker identifies a vulnerable YesWiki instance running a version prior to 4.6.7. Second, the attacker constructs a malicious HTTP request directed at the public actor inbox route. Third, in this request, the attacker includes a crafted Signature header containing a keyId parameter, where the URL points to an IPv6 representation of an internal target (such as a 6to4 or NAT64 representation of localhost or the cloud metadata endpoint). Fourth, the YesWiki server receives the request and invokes the validateKeyIdUrl() function to verify the keyId URL. Fifth, due to the parsing flaw, the validation checks fail to flag the address as restricted, allowing the server to initiate an outbound HTTP connection to the target specified by the attacker. Finally, the server returns or processes the response from the internal host, facilitating unauthorized interaction with internal services. This post-exploitation phase can allow attackers to retrieve sensitive configuration data, access local administrative panels, or query cloud metadata APIs to obtain temporary IAM credentials, leading to full system compromise."
}
CVE-2026-104458: YesWiki SSRF Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere