Vulnerability GO-2026-5996
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 17, 2026 at 07:42 PM UTC
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive
v0.0.1 - v0.29.0
v0.0.1 - v0.29.0
Summary
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive
Details
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
4 hours ago
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive
v0.0.1 - v0.30.0 GO-2026-6526
v0.0.1 - v0.30.0 GO-2026-6526
High Risk
10 days ago
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
v0.0.1 - v0.30.0 GHSA-qg2g-g9w3-m5h8
v0.0.1 - v0.30.0 GHSA-qg2g-g9w3-m5h8
Unknown
2 months ago
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive
v0.0.1 - v0.30.1 GO-2026-6002
v0.0.1 - v0.30.1 GO-2026-6002
Medium Risk
2 months ago
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
v0.0.1 - v0.30.1 GHSA-pr64-jmmf-jp54
v0.0.1 - v0.30.1 GHSA-pr64-jmmf-jp54
Low Risk
2 months ago
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
v0.0.1 - v0.29.0 GHSA-pph6-vfjv-vpjw
v0.0.1 - v0.29.0 GHSA-pph6-vfjv-vpjw
Impacted packages
Timeline
Published
2 months ago
July 17, 2026 at 07:42 PM UTC
Last Modified
2 months ago
July 21, 2026 at 07:15 PM UTC