{"id":"CVE-2026-91129","title":"Home Assistant is open source home automation software focused on local control and privacy","summary":"Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ip…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-918"],"vendor":"home-assistant","product":"core","affected":["core < 2026.2.3"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:16:56.433","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91129","references":[{"url":"https://github.com/home-assistant/core/commit/0f3c7ca2772b605c0f3c09c88f35e527ea6ea560","label":"security-advisories@github.com"},{"url":"https://github.com/home-assistant/core/commit/815c708d19aa0c7f59f9ee318b613a5e481a42b3","label":"security-advisories@github.com"},{"url":"https://github.com/home-assistant/core/pull/162941","label":"security-advisories@github.com"},{"url":"https://github.com/home-assistant/core/releases/tag/2026.2.3","label":"security-advisories@github.com"},{"url":"https://github.com/home-assistant/core/security/advisories/GHSA-4ghv-53cq-7wp3","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-4ghv-53cq-7wp3"}],"tags":["nvd","cve.org","ghsa","pip"],"ingestedAt":"2026-09-22T20:10:15.091Z","aliases":["GHSA-4ghv-53cq-7wp3"],"ecosystem":"pip","patched":["homeassistant 2026.2.3"],"slug":"CVE-2026-91129","body":"## Overview\n\nHome Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port, and base_path values to validate_input for printer metadata retrieval. Because the shared HTTP client followed attacker-controlled cross-origin redirects without blocking loopback targets, a local-network attacker could redirect the request to 127.0.0.1 or another internal service without user interaction or prior IPP configuration. This issue is fixed in version 2026.2.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-91129)\n\nAffected packages:\n\n- `homeassistant < 2026.2.2`\n\nPatched in:\n\n- `homeassistant 2026.2.3`\n\nSource: https://github.com/advisories/GHSA-4ghv-53cq-7wp3","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}