Vulnerability Report: GO-2026-6440
- CVE-2026-73087, GHSA-p2w3-6x73-2f6x
- Affects: github.com/amir20/dozzle
- Published: Sep 10, 2026
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
For detailed information about this vulnerability, visit https://github.com/amir20/dozzle/security/advisories/GHSA-p2w3-6x73-2f6x or https://nvd.nist.gov/vuln/detail/CVE-2026-73087.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/amir20/dozzle/security/advisories/GHSA-p2w3-6x73-2f6x
- https://nvd.nist.gov/vuln/detail/CVE-2026-73087
- https://github.com/amir20/dozzle/commit/8cf7ccd5ee041ecaea92b49951793d4d2393761f
- https://github.com/amir20/dozzle/pull/4887
- https://github.com/amir20/dozzle/releases/tag/v10.6.15
- https://vuln.go.dev/ID/GO-2026-6440.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.