๐Ÿ” CVE Alert

CVE-2026-76898

UNKNOWN 0.0

draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and fd00::, but the JDK returns the expanded address form, so the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, is not blocked. An unauthenticated request to /embed2.js?fetch= can therefore make src/main/java/com/mxgraph/online/EmbedServlet2.java fetch an IPv6 ULA internal resource and reflect the response to the requester. Utils.validatedAddress() uses the same private-address check for the separate ProxyServlet path, which requires ENABLE_DRAWIO_PROXY=1. The primary /embed2.js path requires no proxy feature flag or DNS rebinding, and it can disclose cloud metadata credentials or data from other IPv6-reachable internal services. This issue is fixed in version 30.3.8.

CWE CWE-918
Vendor jgraph
Product drawio
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for jgraph drawio

Be the first to know when new unknown vulnerabilities affecting jgraph drawio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

jgraph / drawio
< 30.3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jgraph/drawio/security/advisories/GHSA-m3q9-cwfq-hcjc github.com: https://github.com/jgraph/drawio/commit/73c4a91196246bbdb60f52b15871e82006b7972d github.com: https://github.com/jgraph/drawio/releases/tag/v30.3.8