THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pgwh-4jj4-qm8v (high) — Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

[GHSA] GHSA-pgwh-4jj4-qm8v (high) — Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

medgithub_advisoriesPublished 2026-07-30

GHSA-pgwh-4jj4-qm8v Severity: high CVE: CVE-2026-67428

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pgwh-4jj4-qm8v