CVE-2026-47684: falha de alta gravidade em Sync-in server
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.7epss 0.4%
probabilidade de exploração
0.4%top 71% das CVEs
exploração observada
nãonenhuma fonte reporta
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Produtos afetados
Sync-in · serverCVEs relacionadas — Sync-in server
No mesmo produto, das mais perigosas para as menos.
CVE-2026-41161MEDIUMUsername Enumeration via Timing AttackEPSS 0.5%CVE-2026-58270MEDIUMSync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`EPSS 0.3%CVE-2026-58272MEDIUMSync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)EPSS 0.3%CVE-2026-58269HIGHSync-in Server has a complete 2FA Bypass via `POST /api/auth/token`EPSS 0.2%CVE-2026-58271MEDIUM@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`EPSS 0.2%