CVE-2026-27129

MEDIUM

Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - SSRF

Title source: llm
STIX 2.1

Description

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has only AAAA (IPv6) records, the function returns the hostname string itself, causing the blocklist comparison to always fail and completely bypassing SSRF protection. This is a bypass of the security fix for CVE-2025-68437. Exploitation requires GraphQL schema permissions for editing assets in the `<VolumeName>` volume and creating assets in the `<VolumeName>` volume. These permissions may be granted to authenticated users with appropriate GraphQL schema access and/or Public Schema (if misconfigured with write permissions). Versions 4.16.19 and 5.8.23 patch the issue.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 1.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-918
Status published
Products (3)
craftcms/cms 5.0.0-RC1 - 5.8.23Packagist
craftcms/craft_cms 5.0.0 (2 CPE variants)
craftcms/craft_cms 3.5.0 - 4.16.19
Published Feb 24, 2026
Tracked Since Feb 24, 2026