THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w98g-5w9p-p3rc (high) — Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

[GHSA] GHSA-w98g-5w9p-p3rc (high) — Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

highgithub_advisoriesPublished 2026-08-28

GHSA-w98g-5w9p-p3rc Severity: high CVE: CVE-2026-55245

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

## Summary

`isPublicIP` in `core/providers/utils/fetch.go` — the SSRF deny-list that gates `FetchAndEncodeURL` — does not reject several routable address ranges that map onto internal infrastructure. Carrier-Grade NAT (`100

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w98g-5w9p-p3rc