What is CVE-2026-67424?
CVE-2026-67424 is a URL validation weakness in the HTTP modules of Flyto2 Core prior to version 2.26.7. The `http.get`, `http.request`, and `http.batch` modules only validate the initial URL, potentially allowing SSRF and other attacks. Users should immediately upgrade to version 2.26.7 or later.
Azərbaycanca: CVE-2026-67424 Flyto2 Core-un HTTP modullarında URL validasiyası zəifliyidir. 2.26.7 öncəsi versiyalarda `http.get`, `http.request` və `http.batch` yalnız ilkin URL-i yoxlayır, bu da SSRF və digər hücumlara səbəb ola bilər. İstifadəçilər dərhal 2.26.7 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which components are affected by CVE-2026-67424?
This weakness affects the `http.get`, `http.request`, and `http.batch` modules.
What version should be upgraded to in order to fix this issue?
Users should upgrade to Flyto2 Core version 2.26.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.