CVE-2026-73297
Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validate_url to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.
| CWE | CWE-918 |
| Vendor | microsoft |
| Product | ufo |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Aug 12, 2026 |
| Last Updated | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for microsoft ufo
Be the first to know when new unknown vulnerabilities affecting microsoft ufo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
microsoft / UFO
< 3.0.8