PatchSiren

cc-tweaked CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM cc-tweaked CVE published 2026-08-27

CVE-2026-55758

This debrief provides an analysis of CVE-2026-55758, a vulnerability in the CC: Tweaked mod for Minecraft. The issue allows an unauthenticated user to execute Lua code and access loopback, RFC 1918, cloud metadata, or internal API endpoints on a dual-stack server using RFC 8215 NAT64. Defenders of Minecraft servers using the CC: Tweaked mod, especially those with Lua code execution capabilities, should as [truncated]