Server-side Request Forgery Risk in CC: Tweaked Mod for Minecraft
CVE-2026-47695

7.1HIGH

Key Information:

Vendor

Cc-tweaked

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47695?

CC: Tweaked is a Minecraft mod that enhances gameplay by integrating programmable computers and turtles. However, up until version 1.119.0, its HTTP API contained a vulnerability that allowed attackers on IPv6-capable networks using NAT64 to bypass protections intended to prevent SSRF. An attacker with the ability to execute Lua code could exploit this flaw by sending requests using well-known NAT64 prefix addresses, allowing access to internal IPv4 services that should have been secured. This poses a significant risk in cloud environments where IPv6-only subnets are commonplace, such as on platforms like AWS and GCP. The issue has been addressed in version 1.119.0.

Affected Version(s)

CC-Tweaked < 1.119.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.