CVE-2026-102577Medium· 4.3▾ SunlitA flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102581Medium· 4.6A flaw was found in Moodle
CVE-2026-102579Medium· 4.3A flaw was found in Moodle
CVE-2026-102578Medium· 5.5A flaw was found in Moodle
CVE-2026-102585Medium· 4.3A flaw was found in Moodle
CVE-2026-102582Low· 2.2A flaw was found in Moodle
CVE-2026-102584Medium· 4.3A flaw was found in Moodle