CVE-2026-102577: Server-Side Request Forgery (SSRF)
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
AI Analysis
Technical Summary
The vulnerability in Moodle arises from incorrect processing of IPv4-mapped IPv6 addresses within the URL downloader component's host-blocking mechanism. An authenticated remote attacker can exploit this by crafting URLs that circumvent host restrictions, resulting in SSRF where the server is induced to send requests to otherwise blocked internal or external resources. This flaw does not require user interaction beyond authentication and impacts confidentiality with limited impact on integrity and availability.
Potential Impact
An authenticated attacker can bypass host-blocking restrictions and cause the Moodle server to make unauthorized HTTP requests to restricted or internal network destinations. This may lead to information disclosure or interaction with internal services not intended to be accessible externally. The impact is limited to confidentiality with no direct integrity or availability effects reported.
Mitigation Recommendations
Patch status is not yet confirmed—check the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-102577 for current remediation guidance. Until an official fix is available, restrict authenticated user capabilities where possible and monitor for unusual URL downloader activity. No vendor advisory states that no action is required or that the issue is already mitigated.
CVE-2026-102577: Server-Side Request Forgery (SSRF)
Description
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
CVSS v3.1
Score 4.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Moodle arises from incorrect processing of IPv4-mapped IPv6 addresses within the URL downloader component's host-blocking mechanism. An authenticated remote attacker can exploit this by crafting URLs that circumvent host restrictions, resulting in SSRF where the server is induced to send requests to otherwise blocked internal or external resources. This flaw does not require user interaction beyond authentication and impacts confidentiality with limited impact on integrity and availability.
Potential Impact
An authenticated attacker can bypass host-blocking restrictions and cause the Moodle server to make unauthorized HTTP requests to restricted or internal network destinations. This may lead to information disclosure or interaction with internal services not intended to be accessible externally. The impact is limited to confidentiality with no direct integrity or availability effects reported.
Mitigation Recommendations
Patch status is not yet confirmed—check the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-102577 for current remediation guidance. Until an official fix is available, restrict authenticated user capabilities where possible and monitor for unusual URL downloader activity. No vendor advisory states that no action is required or that the issue is already mitigated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- fedora
- Date Reserved
- 2026-09-29T14:03:38.493Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-102577","vendor":"Red Hat"}]
Threat ID: 6abccd66c8a85a770d135e48
Added to database: 09/30/2026, 08:50:46 UTC
Last enriched: 09/30/2026, 09:05:45 UTC
Last updated: 09/30/2026, 10:06:05 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.