Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4x5-8cj6-52wg | Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sync-in
Sync-in server |
|
| Vendors & Products |
Sync-in
Sync-in server |
Tue, 16 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue. | |
| Title | Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-16T17:10:12.548Z
Reserved: 2026-05-19T21:18:20.402Z
Link: CVE-2026-47684
Updated: 2026-06-16T17:01:51.847Z
Status : Deferred
Published: 2026-06-16T15:16:41.063
Modified: 2026-06-16T19:16:55.613
Link: CVE-2026-47684
No data.
OpenCVE Enrichment
Updated: 2026-06-17T21:45:02Z
Github GHSA