CVE-2026-69257 is a server-side request forgery vulnerability in Flowise before version 3.1.3. Flowise's HTTP security logic failed to normalize IPv4-mapped IPv6 addresses before applying IPv4 CIDR deny-list validation. Because the address-parsing library classified mapped addresses as IPv6, the deny-list routine skipped IPv4 range checks. This affects Flowise request paths including HTTP Node, API Chain, Document Loader, MCP tooling, and other features using the centralized secure request and deny-list validation functions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Flowise vulnerability allowing SSRF protection bypass using IPv4-mapped IPv6 addresses, potentially exposing internal services, cloud metadata endpoints, credentials, and sensitive information.
A high-severity Flowise SSRF deny-list bypass caused by failure to normalize IPv4-mapped IPv6 addresses. Affected request paths can be directed to localhost, internal services, or cloud metadata endpoints when an attacker controls hostname DNS resolution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.