ZDI-CAN-28279: ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
Published Aug 12, 2026
·Updated
This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.
Affected Software
1 affected component
Home Assistant Green
Event History
Aug 12, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28279?
The severity of ZDI-CAN-28279 is classified with a CVSS rating of 5.4.
2
How do I fix ZDI-CAN-28279?
To fix ZDI-CAN-28279, ensure that you update to the latest version of Home Assistant Green that addresses this vulnerability.
3
Who is affected by ZDI-CAN-28279?
Any users of Home Assistant Green installations are affected by ZDI-CAN-28279.
4
What type of attack does ZDI-CAN-28279 involve?
ZDI-CAN-28279 involves a server-side request forgery (SSRF) vulnerability that allows unauthorized requests.
5
Is authentication required to exploit ZDI-CAN-28279?
No, authentication is not required to exploit ZDI-CAN-28279.