Executive brief
The webhook validation system in Vulnerability Lookup's notification service fails to properly block requests to private and internal endpoints by incorrectly classifying certain IPv6 transition addresses (such as NAT64, 6to4, and Teredo) as public. An authenticated attacker can register a webhook pointing to a hostname that resolves to these transition addresses to bypass security restrictions and exfiltrate vulnerability data to internal systems, including metadata endpoints used by cloud infrastructure.
Technical details
The vulnerability exists in `website/notifications/webhooks.py`, where the webhook URL validator uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`, and IPv4-mapped addresses) are classified as globally routable by IANA, causing `is_global` to return `True` even when the embedded IPv4 address targets private ranges, loopback addresses, or cloud metadata services. The attack requires an authenticated user and a network where DNS resolution can be performed, but the subsequent DNS-pinning defense does not prevent delivery to the malicious target. The fix, already merged to HEAD, extracts the embedded IPv4 from transition addresses and rejects targets when that IPv4 is not globally routable, while still allowing legitimate transition addresses pointing to public IPv4 endpoints.
Affected products
- Vulnerability Lookup Vulnerability Lookup HEAD (non-release versions only)
Timeline
- 2026-08-10: disclosed
- 2026-08-10: patched