PatchSiren

flytohub CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM flytohub CVE published 2026-08-13

CVE-2026-73530

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability. Attackers can submit requests or trigger 302 redirects to bypass private IP range and blocked hostname checks, reaching services bound to IPv6 loopback across http.get, http.request, and http.batch modules. This vulnerability allows attackers to potentially access internal services, which could lead to unauthorize [truncated]