Bypass Vulnerability in Sync-in Server's Private IP Blocklist Regex
CVE-2026-47684
7.7HIGH
What is CVE-2026-47684?
The Sync-in Server prior to version 2.3.0 contains a vulnerability in its URL download feature, where the regex for the private IP blocklist fails to match IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1. This loophole enables potential SSRF attacks on systems utilizing dual-stack addressing, thereby compromising the intended security protections. Users are advised to upgrade to version 2.3.0 or later to mitigate this issue.
Affected Version(s)
server < 2.3.0
