๐Ÿ” CVE Alert

CVE-2026-105689

UNKNOWN 0.0

Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.

CWE CWE-918
Vendor penpot
Product penpot
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for penpot penpot

Be the first to know when new unknown vulnerabilities affecting penpot penpot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

penpot / penpot
< 2.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/penpot/penpot/security/advisories/GHSA-wxgm-8qjw-x445 github.com: https://github.com/penpot/penpot/commit/326d83e780ae120b45ccd6f3d7bd24922b54461c github.com: https://github.com/penpot/penpot/releases/tag/2.18.0