CVE-2026-73297 | Microsoft UFO up to 3.0.7 url_security.py _is_blocked_ip server-side request forgery

SecurityVulns

A vulnerability was found in Microsoft UFO up to 3.0.7. It has been rated as critical. This vulnerability affects the function _is_blocked_ip of the file ufo/utils/url_security.py. This manipulation causes server-side request forgery.

This vulnerability is registered as CVE-2026-73297. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More