Flytohub patched Flyto2 Core in version 2.26.7 to fix several high-severity server-side request forgery flaws that could let remote attackers reach internal services and cloud metadata endpoints. One issue, tracked as CVE-2026-67428, affected multiple HTTP-capable modules and inline base_url handling that accepted caller-controlled URLs without applying the platform’s validate_url_with_env_config safeguard. Another, CVE-2026-67424, allowed modules including http.get, http.request, and http.batch to validate only the initial URL and then follow redirects into internal address space without rechecking each hop, potentially exposing internal response data.
A separate flaw, CVE-2026-67426, exposed the standalone flyto-verification service through an unauthenticated POST /run endpoint on 0.0.0.0:8344 that trusted a user-supplied callback_url and sent an outbound request containing the X-Internal-Key header populated from $FLYTO_RUNNER_SECRET, enabling SSRF and secret exfiltration. Flytohub’s remediation adds per-request and per-redirect URL validation, blocks access to internal and metadata targets across HTTP, GraphQL, webhook, browser, vision, and monitoring modules, and now requires an X-Internal-Key shared secret for /run, with the service failing closed if no secret is configured.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A Flytohub code commit remediated multiple SSRF issues in Flyto Core and hardened the verification service by requiring an X-Internal-Key on /run, adding per-redirect SSRF revalidation, and expanding outbound URL validation across affected modules. The commit also added protections against requests to internal or metadata endpoints and included tests for the new controls.
Flytohub released Flyto Core version 2.26.7 to fix three disclosed vulnerabilities: redirect-based SSRF in guarded HTTP modules, unauthenticated callback_url SSRF with runner-secret exfiltration in flyto-verification, and missing SSRF validation in multiple HTTP-capable modules. The disclosures reference the release, advisory material, and the fixing commit as the remediation for affected versions earlier than 2.26.7.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.