THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p2w3-6x73-2f6x (low) — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

[GHSA] GHSA-p2w3-6x73-2f6x (low) — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

highgithub_advisoriesPublished 2026-09-08

GHSA-p2w3-6x73-2f6x Severity: low CVE: CVE-2026-73087

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

## Summary

The `isBlockedIP` SSRF guard in Dozzle's webhook notification dispatcher blocks loopback, link-local, multicast, and unspecified addresses but does not recognize IPv6 transition mechanism addresses (RFC 3056 6to4, RFC 605

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p2w3-6x73-2f6x