THREAT OPS › Threat News › [GHSA] GHSA-p2w3-6x73-2f6x (low) — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
[GHSA] GHSA-p2w3-6x73-2f6x (low) — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
GHSA-p2w3-6x73-2f6x Severity: low CVE: CVE-2026-73087
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
## Summary
The `isBlockedIP` SSRF guard in Dozzle's webhook notification dispatcher blocks loopback, link-local, multicast, and unspecified addresses but does not recognize IPv6 transition mechanism addresses (RFC 3056 6to4, RFC 605
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- b9df31356fc024e6768a1aac605844dc041d95eesha1
- CVE-2026-73087cve
- tonghuaroot@gmail.comemail
- 127.0.0.0/8cidr
- 169.254.0.0/16cidr
- 2001:0000:dead:beef:0000:0000:7f00:0001ipv6
Original source: https://github.com/advisories/GHSA-p2w3-6x73-2f6x