Improper Input Validation in HomeBox by SysAdmins Media
CVE-2026-55473

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-55473?

HomeBox prior to version 0.26.0 contains an improper input validation issue related to BlockBogonNets and BlockCloudMetadata notifier protections. This vulnerability allows authenticated users to exploit the SSRF mechanism by submitting crafted requests that can target internal IPv4 addresses through NAT64 prefixes. The underlying flaw lies in the incorrect classification of IPv6 destinations as safe, leading to potential disclosure of sensitive metadata such as temporary credentials. This vulnerability has been resolved in version 0.26.0.

Affected Version(s)

homebox < 0.26.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.