PatchSiren cyber security CVE debrief
CVE-2026-55473 sysadminsmedia CVE debrief
An authenticated user can submit a crafted notifier through POST /v1/notifiers or POST /v1/notifiers/test, potentially disclosing retrieved metadata such as temporary credentials on a Homebox instance that egresses through NAT64/DNS64. This medium-severity vulnerability affects Homebox instances with notifier features in use, particularly those with NAT64/DNS64 egress configurations. Defenders should assess exposure and verify configurations to prevent potential metadata disclosure. The vulnerability is fixed in version 0.26.0.
- Vendor
- sysadminsmedia
- Product
- homebox
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-29
Who should care
Defenders and administrators of Homebox instances, especially those with notifier features in use, should assess exposure and verify configurations to prevent potential metadata disclosure.
Why it matters
CVE-2026-55473 is a medium-severity vulnerability in Homebox that allows an authenticated user to potentially disclose retrieved metadata through crafted notifier submissions, requiring defenders to verify exposure and assess NAT64/DNS64 egress configurations.
- Potential disclosure of retrieved metadata such as temporary credentials
- Verification of NAT64/DNS64 egress configurations and notifier feature usage
- Review and update of notifier URL validation to inspect IPv4 destinations in NAT64 prefixes
Technical summary
The default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in Homebox do not inspect IPv4 destinations embedded in NAT64 prefixes, allowing an authenticated user to potentially disclose retrieved metadata. This vulnerability is due to the lack of inspection of IPv4 destinations in NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. The issue is fixed in version 0.26.0, which updates the SSRF protections to correctly classify these destinations as unsafe. Defenders should prioritize verifying exposure and assessing NAT64/DNS64 egress configurations for Homebox instances, especially those with notifier features in use.
Defensive priority
Defenders should prioritize verifying exposure and assessing NAT64/DNS64 egress configurations for Homebox instances, especially those with notifier features in use.
Recommended defensive actions
- Verify Homebox instance configurations for NAT64/DNS64 egress and notifier features
- Assess exposure for authenticated users with notifier submission capabilities
- Review and update notifier URL validation to inspect IPv4 destinations embedded in NAT64 prefixes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the scope of affected deployments and potential impact require further verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55473 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55473
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55473 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55473
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sysadminsmedia/homebox/commit/42c52f7f7566b7fbd8017352187af20f552a4471
-
Source reference
Unverified legacy reference
URL: https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0
-
Source reference
Unverified legacy reference
URL: https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-r9pf-rg22-655m
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.