{"apiVersion":"1.0","identifier":"CVE-2026-74905","description":"SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. The function only checks for loopback, link-local unicast, private, and unspecified addresses and does not recognize IPv6 transition addresses (NAT64 64:ff9b::/96, 6to4 2002::/16, Teredo 2001::/32) that embed private IPv4 destinations. When SafeMode is enabled, an authenticated attacker can bypass the SSRF guard via the network forward proxy, WebSocket proxy, or SSE proxy endpoints by supplying a URL whose hostname resolves to such a transition address, reaching internal services and cloud metadata endpoints (e.g., 169.254.169.254). Because the forward proxy returns the full response body, this is a full-read SSRF that can be used to steal instance credentials, reach internal services, and port-scan internal infrastructure.","publishedAt":"2026-08-18T12:19:30","lastModifiedAt":"2026-08-26T17:04:11","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74905","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","epssProbability":0.00317,"riskScore":0.73,"affectedProduct":"SiYuan","affectedVersions":"<3.7.4","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74905","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74905","en":"https://www.redsauce.net/en/cves/CVE-2026-74905","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74905","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74905","de":"https://www.redsauce.net/de/cves/CVE-2026-74905","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74905","el":"https://www.redsauce.net/el/cves/CVE-2026-74905"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74905"}}