Improper Input Validation in HomeBox by SysAdmins Media
CVE-2026-55473
6MEDIUM
What is CVE-2026-55473?
HomeBox prior to version 0.26.0 contains an improper input validation issue related to BlockBogonNets and BlockCloudMetadata notifier protections. This vulnerability allows authenticated users to exploit the SSRF mechanism by submitting crafted requests that can target internal IPv4 addresses through NAT64 prefixes. The underlying flaw lies in the incorrect classification of IPv6 destinations as safe, leading to potential disclosure of sensitive metadata such as temporary credentials. This vulnerability has been resolved in version 0.26.0.
Affected Version(s)
homebox < 0.26.0
