ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
Published Aug 12, 2026
·Updated
This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.
Affected Software
1 affected component
Home Assistant Green
Event History
Aug 12, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-563?
The severity of ZDI-26-563 is rated at 5.4 according to the CVSS system.
2
How do I fix ZDI-26-563?
To fix ZDI-26-563, update your Home Assistant Green installation to the latest version that contains the security patch.
3
Who can exploit ZDI-26-563?
ZDI-26-563 can be exploited by network-adjacent attackers without any authentication.
4
What does ZDI-26-563 allow attackers to do?
ZDI-26-563 allows attackers to initiate arbitrary server-side requests on vulnerable installations of Home Assistant Green.
5
When was ZDI-26-563 published?
ZDI-26-563 was published on August 12, 2026.