The Lab · 2026-04-06 14:27:17 · GitHub Issues
A critical security vulnerability in the widely-used Go programming language's `golang.org/x/net` library has been patched, addressing a flaw that could allow attackers to bypass proxy restrictions. The vulnerability, tracked as CVE-2025-22870, stems from improper handling of IPv6 addresses with zone identifiers, poten...
The Lab · 2026-04-15 04:22:34 · GitHub Issues
A critical security vulnerability in a notification handler's webhook URL validation allows attackers to bypass internal network protections using IPv6 addresses. The flaw, marked as high severity, resides in the `notifications:save-webhook` IPC handler within the codebase. The validation logic incorrectly compares the...
The Lab · 2026-04-16 15:22:54 · Habr
В IETF появился черновик протокола, который выглядит как спасение от всех проблем современного интернета. Документ draft-thain-ipv8-00, опубликованный 14 апреля 2026 года, обещает мир без dual-stack, без CGNAT и без мучительного двадцатилетнего перехода на IPv6. На бумаге это выглядит слишком хорошо, чтобы быть правдой...
The Lab · 2026-05-09 20:01:44 · GitHub Issues
A defense-in-depth update has identified five IPv6 transition and reserved prefixes that can bypass traditional SSRF protections, including NAT64-wrapped routes to internal metadata services. The blocked ranges include 6to4, Teredo tunneling, NAT64 well-known and local-use prefixes, and a discard-only sinkhole prefix—e...