CVE-2026-22245: Ruby Ipv4 Mapped Ipv6 Ssrf Bypass
An IP restriction blocklist is defined using array literals of `IPAddr` instances without explicitly accommodating IPv4-mapped IPv6 addresses. This can allow Server-Side Request Forgery (SSRF) if an attacker uses the `::ffff:` prefix for an IPv4 address (e.g. `::ffff:127.0.0.1`), bypassing pure IPv4 ranges. Ensure that `.ipv4_mapped` variants are explicitly
greprules fetch cve-2026-22245-ruby-ipv4-mapped-ipv6-ssrf-bypass --engine opengrepDescription
An IP restriction blocklist is defined using array literals of `IPAddr` instances without explicitly accommodating IPv4-mapped IPv6 addresses. This can allow Server-Side Request Forgery (SSRF) if an attacker uses the `::ffff:` prefix for an IPv4 address (e.g. `::ffff:127.0.0.1`), bypassing pure IPv4 ranges. Ensure that `.ipv4_mapped` variants are explicitly
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.