CVE-2026-105689: Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download

Published Oct 5, 2026
·
Updated

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.

Affected Software

1 affected component
Penpot Penpot<2.18.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Penpot to a version that resolves this vulnerability.

    Fixed in 2.18.0

Event History

Oct 5, 2026
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are most exposed to this issue?

Penpot deployments prior to 2.18.0 that use a NAT64 gateway are directly exploitable. Deployments may also be exposed when an attacker can control a DNS AAAA record that resolves to a crafted IPv6 transition address.

2

What level of attacker control is needed?

An attacker needs control of a media import URL, or administrator-level control of a webhook URL. They can use NAT64, 6to4, or Teredo IPv6 transition addresses that embed an IPv4 loopback, link-local, private, or cloud-metadata target.

3

What can an attacker obtain through each affected feature?

Media import can disclose the bodies of responses retrieved from internal targets. Webhook delivery can reveal response status, enabling network probing as a side channel.

4

What version fixes the issue?

Upgrade Penpot to version 2.18.0, which fixes the SSRF guard bypass.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203