CVE-2026-67428 | flytohub flyto-core up to 2.26.6 HTTP Request requests.py validate_url_with_env_config base_url server-side request forgery

SecurityVulns

A vulnerability classified as critical has been found in flytohub flyto-core up to 2.26.6. This affects the function validate_url_with_env_config of the file src/core/modules/third_party/developer/http/requests.py of the component HTTP Request Handler. Performing a manipulation of the argument base_url results in server-side request forgery.

This vulnerability was named CVE-2026-67428. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More