CVE-2026-47684: high-severity vulnerability in Sync-in server
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
Sync-in · serverRelated CVEs — Sync-in server
In the same product, most dangerous first.
CVE-2026-41161MEDIUMUsername Enumeration via Timing AttackEPSS 0.5%CVE-2026-58270MEDIUMSync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`EPSS 0.3%CVE-2026-58272MEDIUMSync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)EPSS 0.3%CVE-2026-58269HIGHSync-in Server has a complete 2FA Bypass via `POST /api/auth/token`EPSS 0.2%CVE-2026-58271MEDIUM@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`EPSS 0.2%