๐Ÿ” CVE Alert

CVE-2026-73297

UNKNOWN 0.0

Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validate_url to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.

CWE CWE-918
Vendor microsoft
Product ufo
Ecosystems
Industries
TechnologyEnterprise
Published Aug 12, 2026
Last Updated Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft ufo

Be the first to know when new unknown vulnerabilities affecting microsoft ufo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

microsoft / UFO
< 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/UFO/security/advisories/GHSA-7hrg-r8xr-p8gr github.com: https://github.com/microsoft/UFO/commit/96983c73ed09e884a5f1d7ff8936c953b234b684 github.com: https://github.com/microsoft/UFO/releases/tag/v3.0.8