CVE-2026-22245: Ruby Ipv4 Mapped Ipv6 Ssrf Bypass

An IP restriction blocklist is defined using array literals of `IPAddr` instances without explicitly accommodating IPv4-mapped IPv6 addresses. This can allow Server-Side Request Forgery (SSRF) if an attacker uses the `::ffff:` prefix for an IPv4 address (e.g. `::ffff:127.0.0.1`), bypassing pure IPv4 ranges. Ensure that `.ipv4_mapped` variants are explicitly

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2026-22245-ruby-ipv4-mapped-ipv6-ssrf-bypass --engine opengrep

Description

An IP restriction blocklist is defined using array literals of `IPAddr` instances without explicitly accommodating IPv4-mapped IPv6 addresses. This can allow Server-Side Request Forgery (SSRF) if an attacker uses the `::ffff:` prefix for an IPv4 address (e.g. `::ffff:127.0.0.1`), bypassing pure IPv4 ranges. Ensure that `.ipv4_mapped` variants are explicitly