Executive brief
ArcadeDB is a NoSQL database that provides import and server restore functionality. Authenticated users can exploit incomplete IPv6 address validation in the SSRF protection to reach internal services and cloud metadata endpoints by supplying specially crafted hostnames. This allows attackers with import permissions to exfiltrate sensitive data from systems that should be protected from external access.
Technical details
The vulnerability exists in ImportSecurityValidator.isBlockedAddress() and PostServerCommandHandler.isBlockedHost(), which use Java InetAddress flag methods to block requests to internal addresses. These methods fail to detect IPv6 transition addresses (NAT64, 6to4, Teredo) that embed RFC 1918 private or loopback IPv4 addresses. An attacker with IMPORT DATABASE or server command permission can supply a URL that resolves to one of these transition forms (e.g., 64:ff9b::c0a8:0101 for NAT64-encoded 192.168.1.1) to bypass the SSRF guard. The SafeHttpFetcher's redirect-following and DNS-pinning mitigations do not compensate because the attacker can point directly to a transition address via DNS, avoiding redirects. Patched in version 26.9.1.
Affected products
- ArcadeDB ArcadeDB before 26.9.1
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: version 26.9.1