{"id":"CVE-2026-85692","summary":"Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding","details":"Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tools/http.go, the SSRF guard for the http_fetch AI-agent tool. The function only unwraps standard IPv4-mapped (::ffff:a.b.c.d) IPv6 addresses before checking them against the forbidden-range list, and does not classify 6to4 (2002::/16), NAT64 (64:ff9b::/96, 64:ff9b:1::/48), or deprecated site-local (fec0::/10) addresses. On a dual-stack or NAT64-enabled host, an attacker able to supply a URL to the http_fetch tool can bypass the guard by encoding a forbidden IPv4 address (such as the cloud instance-metadata endpoint 169.254.169.254) in one of these IPv6 forms to reach internal or metadata services.","modified":"2026-09-06T03:47:20.362958340Z","published":"2026-09-04T14:32:36.023Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85692.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85692.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85692"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nightingale-9.1.1-ssrf-guard-bypass-via-ipv6-encoding"},{"type":"REPORT","url":"https://github.com/ccfos/nightingale/issues/3363"},{"type":"PACKAGE","url":"https://github.com/ccfos/nightingale"},{"type":"ARTICLE","url":"https://github.com/ccfos/nightingale/blob/v9.1.1/aiagent/tools/http.go"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ccfos/nightingale","events":[{"introduced":"0"},{"last_affected":"4e056150142b2e1ed6966c9317a9e08442c399f7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"9.1.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v9.1.1","v9.1.0","v9.0.0","v9.0.0-beta.4-test","v9.0.0-beta.4","v9.0.0-beta.3","v9.0.0-beta.2","v9.0.0-beta.1","v8.5.1","v8.5.0","v8.3.1","v8.3.0","v8.2.2","v8.2.1","v8.2.0","v8.1.0","v8.0.0","v8.0.0-beta.14","v8.0.0-beta.13","v8.0.0-beta.12","v8.0.0-beta.11","v8.0.0-beta.10","v8.0.0-beta.9","v8.0.0-beta.8.2","v8.0.0-beta.8.1","v8.0.0-beta.8","v8.0.0-beta.7","v8.0.0-beta.6","v8.0.0-beta.5","v8.0.0-beta.4","v8.0.0-beta.3","v8.0.0-beta.2","v8.0.0-beta.1","v7.7.1","v7.6.0","v7.5.0","v7.4.1","v7.4.0","v7.3.3","v7.3.2","v7.3.1","v7.3.0","v7.2.1","v7.2.0","v7.1.0","v7.0.0","v7.0.0-beta.14.1","v7.0.0-beta.14","v7.0.0-beta.14.3","v7.0.0-beta.14.2","v7.0.0-beta.13","v7.0.0-beta.12","v7.0.0-beta.12.1","v7.0.0-beta.10","v7.0.0-beta.9","v7.0.0-beta.8","v7.0.0-beta.7","v7.0.0-beta.5","v7.0.0-beta.3","v7.0.0-beta.2.0.1","v7.0.0-beta.2","v7.0.0-beta.0","v6.7.2","v6.7.1","v6.7.0","v6.6.1","v6.6.0","v6.5.0","v6.4.0","v6.3.4","v6.3.3","v6.3.2","v6.3.1","v6.3.0","v6.0.3","v6.0.2","v6.0.0","v6.0.0-ga.14","v6.0.0-ga.14-pre","v6.0.0-ga.13","v6.0.0-ga.12","v6.0.0-ga.11","v6.0.0-ga.10","v6.0.0-ga.9","v6.0.0-ga.8","v6.0.0-ga.7.0.2","v6.0.0-ga.7.0.1","v6.0.0-ga.7","v6.0.0-ga.6","v6.0.0-ga.5","v6.0.0-ga.4.1","v6.0.0-ga.4.0.1","v6.0.0-ga.4","v6.0.0-ga.3","v6.0.0-ga.2","v6.0.0-ga.1","v6.0.0-beta.5","v6.0.0-beta.4","v6.0.0-beta.3","v6.0.0-beta.2","v6.0.0-beta.1","v6.0.0-beta.0","v5.15.0","v5.14.5","v5.14.4","v5.14.3","v5.14.2","v5.14.1","v5.14.0","v5.13.1","v5.13.0","v5.12.1","v5.12.0","v5.11.3","v5.11.2","v5.11.1","v5.11.0","v5.10.3","v5.10.2","v5.10.1","v5.10.0","v5.9.7","v5.9.6","v5.9.5","v5.9.4","v5.9.3","v5.9.2","v5.8.0","v5.7.0","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v3.8.0","v5.5.0","v5.4.0","v5.3.4","v5.3.3","v5.3.2","v5.3.1","v5.3.0","v5.2.3","v5.2.2","v5.2.0","v5.1.0","v5.0.0-ga-06","v5.0.0-ga-05","v5.0.0-ga-04","v5.0.0-ga-02","v5.0.0-rc7","v4.0.3","v4.0.2","v4.0.0","v3.7.1","v3.7.0","v3.6.0","v3.5.2","v3.5.1","v3.5.0","v3.4.1","v3.4.0","v3.3.1","v3.3.0","v3.1.6","v3.1.4","v2.8.0","v2.7.2","v2.7.1","v2.7.0","v2.0.0","v1.4.0","v2.4.2","v2.2.2","V2.2.1","v2.2.0","V2.1.0","V1.4.1","v1.3.3","V1.3.2","V1.3.1","v1.3.0","v1.2.4","v1.2.3","v1.2.2","v1.2.0","v1.1.0","v1.0.3","v1.0.2","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85692.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}