PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55473 sysadminsmedia CVE debrief

An authenticated user can submit a crafted notifier through POST /v1/notifiers or POST /v1/notifiers/test, potentially disclosing retrieved metadata such as temporary credentials on a Homebox instance that egresses through NAT64/DNS64. This medium-severity vulnerability affects Homebox instances with notifier features in use, particularly those with NAT64/DNS64 egress configurations. Defenders should assess exposure and verify configurations to prevent potential metadata disclosure. The vulnerability is fixed in version 0.26.0.

Vendor
sysadminsmedia
Product
homebox
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-29
Advisory published
2026-09-21
Advisory updated
2026-09-29

Who should care

Defenders and administrators of Homebox instances, especially those with notifier features in use, should assess exposure and verify configurations to prevent potential metadata disclosure.

Why it matters

CVE-2026-55473 is a medium-severity vulnerability in Homebox that allows an authenticated user to potentially disclose retrieved metadata through crafted notifier submissions, requiring defenders to verify exposure and assess NAT64/DNS64 egress configurations.

  • Potential disclosure of retrieved metadata such as temporary credentials
  • Verification of NAT64/DNS64 egress configurations and notifier feature usage
  • Review and update of notifier URL validation to inspect IPv4 destinations in NAT64 prefixes

Technical summary

The default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in Homebox do not inspect IPv4 destinations embedded in NAT64 prefixes, allowing an authenticated user to potentially disclose retrieved metadata. This vulnerability is due to the lack of inspection of IPv4 destinations in NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. The issue is fixed in version 0.26.0, which updates the SSRF protections to correctly classify these destinations as unsafe. Defenders should prioritize verifying exposure and assessing NAT64/DNS64 egress configurations for Homebox instances, especially those with notifier features in use.

Defensive priority

Defenders should prioritize verifying exposure and assessing NAT64/DNS64 egress configurations for Homebox instances, especially those with notifier features in use.

Recommended defensive actions

  • Verify Homebox instance configurations for NAT64/DNS64 egress and notifier features
  • Assess exposure for authenticated users with notifier submission capabilities
  • Review and update notifier URL validation to inspect IPv4 destinations embedded in NAT64 prefixes
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the scope of affected deployments and potential impact require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55473 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55473

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55473 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55473

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.