CVE-2026-55758

Source
https://cve.org/CVERecord?id=CVE-2026-55758
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55758.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55758
Aliases
  • GHSA-2rrx-mch2-76cp
Published
2026-08-27T17:11:00Z
Modified
2026-09-11T08:36:35Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: RFC 8215 NAT64 prefix (64:ff9b:1::/96) bypasses SSRF protection
Details

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, the SSRF protection in projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java blocks the RFC 6052 64:ff9b::/96 NAT64 prefix but omits the RFC 8215 64:ff9b:1::/48 local-use prefix. On a dual-stack server using RFC 8215 NAT64, an unauthenticated user who can execute Lua code can use http.request or http.websocket with an address under 64:ff9b:1::/48 to reach loopback, RFC 1918, cloud metadata, or internal API endpoints because PrivatePattern.matches() does not classify the mapped IPv6 address as private. This issue is fixed in version 1.120.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55758.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "1.120.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/cc-tweaked/cc-tweaked

Affected ranges

Type
GIT
Repo
https://github.com/cc-tweaked/cc-tweaked
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.79
1.80pr0
1.80pr1
v1.*
v1.12.2-1.81.0
v1.12.2-1.81.1
v1.12.2-1.82.0
v1.13.2-1.82.0
v1.13.2-1.82.3
v1.13.2-1.83.1
v1.14.3-1.83.1
v1.14.4-1.84.0
v1.14.4-1.84.1
v1.14.4-1.85.0
v1.14.4-1.85.1
v1.14.4-1.85.2
v1.14.4-1.86.0
v1.14.4-1.86.1
v1.14.4-1.86.2
v1.15.2-1.86.2
v1.15.2-1.87.0
v1.15.2-1.87.1
v1.15.2-1.88.0
v1.15.2-1.88.1
v1.15.2-1.89.0
v1.15.2-1.89.1
v1.16.1-1.90.0
v1.16.1-1.90.1
v1.16.1-1.90.2
v1.16.1-1.90.3
v1.16.2-1.91.0
v1.16.2-1.91.1
v1.16.3-1.92.0
v1.16.3-1.93.0
v1.16.3-1.93.1
v1.16.4-1.94.0
v1.16.4-1.95.0
v1.16.4-1.95.1
v1.16.4-1.95.2
v1.16.4-1.95.3
v1.16.4-1.96.0
v1.16.5-1.97.0
v1.16.5-1.98.0
v1.16.5-1.98.1
v1.17.1-1.98.2
v1.17.1-1.99.0
v1.18-1.99.0
v1.18.1-1.100.0
v1.18.1-1.100.1
v1.18.1-1.100.2
v1.18.1-1.99.1
v1.18.2-1.100.3
v1.18.2-1.100.4
v1.18.2-1.100.5
v1.19-1.100.6
v1.19-1.100.7
v1.19-1.100.8
v1.19.1-1.100.9
v1.19.2-1.100.10
v1.19.2-1.101.0
v1.19.2-1.101.1
v1.19.3-1.102.0
v1.19.3-1.102.1
v1.19.3-1.102.2
v1.19.3-1.103.0
v1.19.3-1.103.1
v1.19.4-1.104.0
v1.20-1.105.0
v1.20.1-1.105.0
v1.20.1-1.106.0
v1.20.1-1.106.1
v1.20.1-1.107.0
v1.20.1-1.108.0
v1.20.1-1.108.1
v1.20.1-1.108.2
v1.20.1-1.108.3
v1.20.1-1.108.4
v1.20.1-1.109.0
v1.20.1-1.109.1
v1.20.1-1.109.2
v1.20.1-1.109.3
v1.20.1-1.109.4
v1.20.1-1.109.5
v1.20.1-1.109.6
v1.20.1-1.109.7
v1.20.1-1.110.0
v1.20.1-1.110.1
v1.20.1-1.110.2
v1.20.1-1.110.3
v1.20.1-1.111.0
v1.20.1-1.112.0
v1.20.1-1.113.0
v1.20.1-1.113.1
v1.20.1-1.114.0
v1.20.1-1.114.1
v1.20.1-1.114.2
v1.20.1-1.114.3
v1.20.1-1.114.4
v1.20.1-1.115.0
v1.20.1-1.115.1
v1.20.1-1.116.0
v1.20.1-1.116.1
v1.20.1-1.116.2
v1.20.1-1.117.0
v1.20.1-1.117.1
v1.20.1-1.118.0
v1.20.1-1.119.0
v1.80pr1.1
v1.80pr1.10
v1.80pr1.11
v1.80pr1.12
v1.80pr1.13
v1.80pr1.14
v1.80pr1.2
v1.80pr1.3
v1.80pr1.4
v1.80pr1.5
v1.80pr1.6
v1.80pr1.7
v1.80pr1.8
v1.80pr1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55758.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "255808885637131291227936825663556948963",
                "89103567853895424379929768058384723699",
                "301815189965289548723740460528896127124",
                "251743794198942377103696026595606399753",
                "155042680660766041430101058826994372885",
                "9134629769773490916723431515762409966",
                "77560368257520274281504463711378818728",
                "231777887374362699877405936552918953943",
                "21869403091953152141610006153146145730",
                "219204172907267424185292292149747706408"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-55758-11783737",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0",
        "target": {
            "file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "56136286324103481683565708597909304793",
                "299604109844233079037653567357256888248",
                "100780412155496749272028092900199864016",
                "222644339674302282029212968176234856439"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-55758-2b3ee022",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0",
        "target": {
            "file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressRule.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "209134531366735862693126308087224479238",
                "1081699440551849938158876364421430395",
                "240623059285766362023144628554425969559",
                "114554393182832445010308674615209604363"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-55758-e8ca6805",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0",
        "target": {
            "file": "projects/core/src/test/java/dan200/computercraft/core/apis/http/options/AddressRuleTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "39888864655999899814819736410754418490",
            "length": 284
        },
        "id": "CVE-2026-55758-ed494057",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/d1bfb2571d3bde55529fac50d8303b7404499ec0",
        "target": {
            "file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java",
            "function": "matches"
        }
    }
]
vanir_signatures_modified
"2026-09-11T08:36:35Z"