{"id":"PYSEC-2026-3569","summary":"Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation","details":"## Summary\nThe HTTP modules that DO call the SSRF guard (`http.get`, `http.request`, `http.batch`) validate only the initial URL, then issue the request with aiohttp's default `allow_redirects=True` and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an internal address; the guard passes on the public host and aiohttp transparently follows the redirect into internal space, returning the internal body.\n\n## Root Cause\n`src/core/modules/atomic/http/get.py:116` calls `session.get(url, ...)` with no `allow_redirects` argument → aiohttp default `True`. `request.py:60` sets `allow_redirects=follow_redirects` (default True at :327); `batch.py:57` likewise. A repo grep of `http/` for `on_request_redirect` / `response.history` returns NONE — there is no redirect interception or Location revalidation.\n\n## Impact\nFull readable SSRF that defeats the primary SSRF control on the very modules that correctly validate. Confidentiality of internal/metadata responses (C:H), S:C.\n\n## Proof of Concept\nVerified live: `http.get` with allowlisted base `127.0.0.1` followed a `302 Location: http://127.0.0.2/...` (non-allowlisted) and returned `INTERNAL-VIA-REDIRECT`.\n```\nattacker hosts http://attacker.tld/r  -\u003e  302 Location: http://\u003ccloud-metadata-ip\u003e/latest/meta-data/...\nexecute_module http.get {\"url\":\"http://attacker.tld/r\"}\n```\n\n## Attack Chain\n1. Entry: `execute_module http.get {url:\"http://attacker.tld/r\"}` (attacker 302-\u003einternal). Guard: `validate_url_with_env_config(url)` (get.py:104). Bypass proof: validation runs on `attacker.tld` (public) → passes; never re-run on the redirect target.\n2. Sink: `session.get(url)` (get.py:116) — no `allow_redirects` arg → aiohttp default True. Bypass proof: grep of `http/` for `on_request_redirect`/`response.history` → NONE.\n3. Impact: aiohttp follows 302 to the internal host; internal body returned (get.py:118).\n\n## Bypass Evidence\nLive PoC followed a 302 into non-allowlisted loopback and returned the internal marker string. aiohttp `ClientSession.get` default `allow_redirects=True`; module never sets it False; no per-hop revalidation exists.\n\n## Affected Versions\n`\u003c= 2.26.6` — `get.py:116`, `request.py:60`, `batch.py:57` present on latest release tag.\n\n## Suggested Fix\nSet `allow_redirects=False` and manually revalidate each `Location` header through `validate_url_with_env_config` before following, or cap and re-check every hop.\n\n## Credit\n\nVulnerability discovered by zx (Jace).","aliases":["CVE-2026-67424","GHSA-c9hr-64h3-gxpc"],"modified":"2026-08-04T14:30:27.320502247Z","published":"2026-08-04T11:34:45.694Z","references":[{"type":"WEB","url":"https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67424"},{"type":"WEB","url":"https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9"},{"type":"PACKAGE","url":"https://github.com/flytohub/flyto-core"},{"type":"WEB","url":"https://github.com/flytohub/flyto-core/releases/tag/v2.26.7"},{"type":"PACKAGE","url":"https://pypi.org/project/flyto-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c9hr-64h3-gxpc"}],"affected":[{"package":{"name":"flyto-core","ecosystem":"PyPI","purl":"pkg:pypi/flyto-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.26.7"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.11.0","1.12.0","1.13.0","1.14.0","1.14.1","1.14.2","1.15.0","1.16.0","1.16.1","1.16.10","1.16.2","1.16.3","1.16.4","1.16.5","1.16.6","1.16.7","1.16.8","1.16.9","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","1.5.2","1.5.4","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","1.8.0","1.8.1","1.8.10","1.8.11","1.8.12","1.8.13","1.8.14","1.8.15","1.8.16","1.8.17","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.9.0","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.10.0","2.11.0","2.12.0","2.12.1","2.12.13","2.12.15","2.12.16","2.12.17","2.12.18","2.12.19","2.12.2","2.12.20","2.12.21","2.12.22","2.12.23","2.12.24","2.12.25","2.12.26","2.12.27","2.12.28","2.12.3","2.12.4","2.12.5","2.12.6","2.13.0","2.13.1","2.13.2","2.13.3","2.13.4","2.14.0","2.15.0","2.15.1","2.15.2","2.15.3","2.16.1","2.16.3","2.16.4","2.17.0","2.17.1","2.17.2","2.17.3","2.17.4","2.17.5","2.17.6","2.17.7","2.17.8","2.18.0","2.18.1","2.18.10","2.18.11","2.18.2","2.18.3","2.18.4","2.18.5","2.18.6","2.18.8","2.18.9","2.19.0","2.2.0","2.2.1","2.2.2","2.20.0","2.20.1","2.20.2","2.20.3","2.20.4","2.23.0","2.23.1","2.23.2","2.23.3","2.24.0","2.24.1","2.24.2","2.24.3","2.24.4","2.25.0","2.25.1","2.25.10","2.25.11","2.25.12","2.25.13","2.25.14","2.25.15","2.25.16","2.25.17","2.25.18","2.25.19","2.25.2","2.25.20","2.25.21","2.25.22","2.25.23","2.25.24","2.25.25","2.25.26","2.25.27","2.25.3","2.25.4","2.25.5","2.25.6","2.25.7","2.25.8","2.25.9","2.26.0","2.26.1","2.26.2","2.26.3","2.26.4","2.26.5","2.3.0","2.3.1","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.8.0","2.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/flyto-core/PYSEC-2026-3569.yaml"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}