{"id":"CVE-2026-55758","summary":"CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: RFC 8215 NAT64 prefix (64:ff9b:1::/96) bypasses SSRF protection","details":"CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, the SSRF protection in projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java blocks the RFC 6052 64:ff9b::/96 NAT64 prefix but omits the RFC 8215 64:ff9b:1::/48 local-use prefix. On a dual-stack server using RFC 8215 NAT64, an unauthenticated user who can execute Lua code can use http.request or http.websocket with an address under 64:ff9b:1::/48 to reach loopback, RFC 1918, cloud metadata, or internal API endpoints because PrivatePattern.matches() does not classify the mapped IPv6 address as private. This issue is fixed in version 1.120.0.","aliases":["GHSA-2rrx-mch2-76cp"],"modified":"2026-09-11T08:36:35.891282Z","published":"2026-08-27T17:11:00.307Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"1.120.0"}]}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55758.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55758.json"},{"type":"ADVISORY","url":"https://github.com/cc-tweaked/CC-Tweaked/security/advisories/GHSA-2rrx-mch2-76cp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55758"},{"type":"FIX","url":"https://github.com/cc-tweaked/CC-Tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cc-tweaked/cc-tweaked","events":[{"introduced":"0"},{"fixed":"d1bfb2571d3bde55529fac50d8303b7404499ec0"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.20.1-1.119.0","v1.20.1-1.118.0","v1.20.1-1.117.1","v1.20.1-1.117.0","v1.20.1-1.116.2","v1.20.1-1.116.1","v1.20.1-1.116.0","v1.20.1-1.115.1","v1.20.1-1.115.0","v1.20.1-1.114.4","v1.20.1-1.114.3","v1.20.1-1.114.2","v1.20.1-1.114.1","v1.20.1-1.114.0","v1.20.1-1.113.1","v1.20.1-1.113.0","v1.20.1-1.112.0","v1.20.1-1.111.0","v1.20.1-1.110.3","v1.20.1-1.110.2","v1.20.1-1.110.1","v1.20.1-1.110.0","v1.20.1-1.109.7","v1.20.1-1.109.6","v1.20.1-1.109.5","v1.20.1-1.109.4","v1.20.1-1.109.3","v1.20.1-1.109.2","v1.20.1-1.109.1","v1.20.1-1.109.0","v1.20.1-1.108.4","v1.20.1-1.108.3","v1.20.1-1.108.2","v1.20.1-1.108.1","v1.20.1-1.108.0","v1.20.1-1.107.0","v1.20.1-1.106.1","v1.20.1-1.106.0","v1.20.1-1.105.0","v1.20-1.105.0","v1.19.4-1.104.0","v1.19.2-1.101.1","v1.19.3-1.103.1","v1.19.3-1.103.0","v1.19.3-1.102.2","v1.19.3-1.102.1","v1.19.3-1.102.0","v1.19.2-1.101.0","v1.19.2-1.100.10","v1.19.1-1.100.9","v1.19-1.100.8","v1.19-1.100.7","v1.19-1.100.6","v1.18.2-1.100.5","v1.18.2-1.100.4","v1.18.2-1.100.3","v1.18.1-1.100.2","v1.18.1-1.100.1","v1.18.1-1.100.0","v1.18.1-1.99.1","v1.18-1.99.0","v1.17.1-1.99.0","v1.17.1-1.98.2","v1.16.5-1.98.1","v1.16.5-1.98.0","v1.16.5-1.97.0","v1.16.4-1.96.0","v1.16.4-1.95.3","v1.16.4-1.95.2","v1.16.4-1.95.1","v1.16.4-1.95.0","v1.16.4-1.94.0","v1.16.3-1.93.1","v1.16.3-1.93.0","v1.16.3-1.92.0","v1.16.2-1.91.1","v1.16.2-1.91.0","v1.16.1-1.90.3","v1.16.1-1.90.2","v1.16.1-1.90.1","v1.16.1-1.90.0","v1.15.2-1.89.1","v1.15.2-1.89.0","v1.15.2-1.88.1","v1.15.2-1.88.0","v1.15.2-1.87.1","v1.15.2-1.87.0","v1.14.4-1.86.2","v1.15.2-1.86.2","v1.14.4-1.86.1","v1.14.4-1.86.0","v1.14.4-1.85.2","v1.14.4-1.85.1","v1.14.4-1.85.0","v1.14.4-1.84.1","v1.14.4-1.84.0","v1.14.3-1.83.1","v1.13.2-1.83.1","v1.13.2-1.82.3","v1.13.2-1.82.0","v1.12.2-1.82.0","v1.12.2-1.81.1","v1.12.2-1.81.0","v1.80pr1.14","v1.80pr1.13","v1.80pr1.12","v1.80pr1.11","v1.80pr1.10","v1.80pr1.9","v1.80pr1.8","v1.80pr1.7","v1.80pr1.6","v1.80pr1.5","v1.80pr1.4","v1.80pr1.3","v1.80pr1.2","v1.80pr1.1","1.80pr1","1.80pr0","1.79"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55758.json","vanir_signatures_modified":"2026-09-11T08:36:35Z","vanir_signatures":[{"digest":{"line_hashes":["255808885637131291227936825663556948963","89103567853895424379929768058384723699","301815189965289548723740460528896127124","251743794198942377103696026595606399753","155042680660766041430101058826994372885","9134629769773490916723431515762409966","77560368257520274281504463711378818728","231777887374362699877405936552918953943","21869403091953152141610006153146145730","219204172907267424185292292149747706408"],"threshold":0.9},"id":"CVE-2026-55758-11783737","signature_type":"Line","signature_version":"v1","source":"https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0","target":{"file":"projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["56136286324103481683565708597909304793","299604109844233079037653567357256888248","100780412155496749272028092900199864016","222644339674302282029212968176234856439"],"threshold":0.9},"id":"CVE-2026-55758-2b3ee022","signature_type":"Line","signature_version":"v1","source":"https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0","target":{"file":"projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressRule.java"}},{"deprecated":false,"digest":{"line_hashes":["209134531366735862693126308087224479238","1081699440551849938158876364421430395","240623059285766362023144628554425969559","114554393182832445010308674615209604363"],"threshold":0.9},"id":"CVE-2026-55758-e8ca6805","signature_type":"Line","signature_version":"v1","source":"https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0","target":{"file":"projects/core/src/test/java/dan200/computercraft/core/apis/http/options/AddressRuleTest.java"}},{"signature_version":"v1","source":"https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0","target":{"function":"matches","file":"projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"},"deprecated":false,"digest":{"function_hash":"39888864655999899814819736410754418490","length":284},"id":"CVE-2026-55758-ed494057","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"}]}