CVE-2026-105689
Deferred Deferred - Pending Action

SSRF Bypass via IPv6 Transition Addresses in Penpot

Vulnerability report for CVE-2026-105689, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Penpot versions before 2.18.0. It allows bypassing SSRF protections by using IPv6 transition addresses like NAT64, 6to4, or Teredo. These addresses embed IPv4 targets that Java's InetAddress checks miss, letting attackers access internal services such as cloud metadata, loopback, or private networks.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Use commands like 'curl -s https://your-penpot-instance.com/api/version' or inspect the Docker image tag if deployed in a container. Also verify if your network routes traffic through NAT64 gateways, which can be checked via 'ip -6 route' or 'traceroute -6'.

Impact Analysis

An attacker with control over a media import URL or webhook URL could exploit this to access sensitive internal services like cloud metadata endpoints (e.g., AWS metadata service) or private networks. Media imports may leak response bodies, while webhooks could expose response status as a side channel for probing networks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data or internal systems, potentially violating GDPR (data protection) or HIPAA (health information privacy) by exposing personal or confidential information through SSRF attacks.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. If upgrading is not possible, block IPv6 transition addresses (NAT64, 6to4, Teredo) at the network firewall level. Review and restrict access to webhook and media import features until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105689. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart