CVE-2026-93597

HIGH Status: Deferred

CVSS Scores

CVSS v3.x Base Score
7.7
HIGH

Description

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.

Published
September 18, 2026 2:19 PM
Last Modified
September 18, 2026 2:19 PM
Source
[email protected]

Weaknesses (CWE)

CWE-918

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.