You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TinyIce 2.11.1 (security)
SSRF via IPv6 transition addresses (GHSA-7r38-rfcc-8x22). The outbound
address policy judged IPv6 literals on the stdlib predicates alone, which
do not look at an embedded IPv4, so a webhook or relay URL written as a
NAT64, 6to4, Teredo or IPv4-compatible address reached the private,
loopback and link-local ranges the policy exists to refuse — including
the cloud metadata endpoint.
The embedded address is now decoded and judged on the same policy.
Transition addresses carrying a public IPv4 are unaffected.
Full notes in CHANGELOG.md.