Junglewise Threat Intelligence

CVE-2026-67424: flytohub flyto-core SSRF via redirect in HTTP modules

CVE-2026-67424 · Severity: high · CVSS 8.5 · Published 2026-07-29

Technologies: flyto-core (PyPI). Vendors: PyPI.

Executive brief

Flyto2 Core contains a security flaw in its HTTP modules that allows attackers to bypass security filters and access internal network resources. While the system checks the initial web address provided, it fails to re-verify the destination if that address redirects to a different location. This could allow an attacker to view sensitive internal data or cloud metadata that should be protected from external access.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Flyto2 Core's HTTP modules (http.get, http.request, http.batch). While these modules utilize an SSRF guard to validate the initial URL, they rely on the aiohttp library's default behavior of automatically following redirects (allow_redirects=True) without re-validating the 'Location' header of subsequent hops. An attacker can provide a public URL that issues a 302 redirect to an internal IP address or cloud metadata service (e.g., 169.254.169.254). Because the guard only checks the first URL, the redirect is followed transparently, allowing the attacker to read internal responses. The issue is fixed in version 2.26.7 by ensuring all redirect hops are validated.

Affected products

  • flytohub flyto-core <= 2.26.6

Timeline

  • 2026-07-08: disclosed
  • 2026-07-29: advisory: NVD publication
  • 2026-07-30: patched: GitHub Advisory published/reviewed

References

Related threats