CVE-2026-47695
CC-Tweaked has an SSRF Protection Bypass with NAT64
CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests to private network ranges to prevent server-side request forgery (SSRF). This protection can be bypassed on IPv6-capable servers using NAT64 well-known prefix addresses (`64:ff9b::/96`). An attacker who can execute Lua code can reach any internal IPv4 service that the filter is intended to block, by addressing it as `http://[64:ff9b::<ipv4-as-hex>]/` instead of its direct IPv4 address. This affects any CC-Tweaked deployment on a network with NAT64 routing โ a configuration that is standard on AWS, GCP, and other cloud platforms when using IPv6-only subnets. Version 1.119.0 fixes the issue.
| CWE | CWE-918 |
| Vendor | cc-tweaked |
| Product | cc-tweaked |
| Published | Jul 21, 2026 |
Get instant alerts for cc-tweaked cc-tweaked
Be the first to know when new unknown vulnerabilities affecting cc-tweaked cc-tweaked are published โ delivered to Slack, Telegram or Discord.