# CVE-2026-72860 — decolua 9router

> As of 2026-08-21, CVE-2026-72860 is a HIGH-severity vulnerability in decolua 9router, CVSS v3.1 8.5, EPSS 0.2% (12.5th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-72860 as of 2026-08-21; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-08-21

## What is CVE-2026-72860?

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.\d+\.\d+)$, but the WHATWG URL parser canonicalizes such literals to hextets before the guard runs, so new URL("http://[::ffff:127.0.0.1]/").hostname yields [::ffff:7f00:1] and the pattern is tested against a string it is never handed. Every IPv4-mapped address therefore passes, and http://[::ffff:7f00:1] and http://[::ffff:a9fe:a9fe] reach loopback and link-local metadata addresses; a hostname whose A record points at an internal address passes as well because no resolution occurs. In the custom-embedding branch the upstream response body is truncated to 200 bytes and returned to the caller whenever the upstream status is neither 2xx nor 401 nor 403, which discloses the beginning of internal responses, and the other validation types remain usable for blind internal port scanning through status and timing differences. The caller-supplied apiKey is forwarded to the internal destination as an Authorization Bearer header. A dashboard session is required by default, and none is required when requireLogin is disabled.

The record classifies CVE-2026-72860 under weakness classes [CWE-918](https://intel.threadlinqs.com/cwe/CWE-918), [CWE-184](https://cwe.mitre.org/data/definitions/184.html). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 46 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 8.5 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N`)
- **CVSS v4.0 base score:** 6.3 (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N`)
- **EPSS (FIRST):** 0.2% probability of exploitation in the next 30 days, higher than 12.5% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 4.8/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-08-20, last modified 2026-08-21

## Is CVE-2026-72860 being exploited?

It currently carries a trending score of 33 in the Threadlinqs vulnerability feed.

## Affected products and versions

- **decolua**: 9router

## How to fix CVE-2026-72860

No vendor patch reference has been recorded for CVE-2026-72860 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-72860

No threat campaign in the Threadlinqs corpus currently references CVE-2026-72860, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories. Last verified by Threadlinqs on 2026-08-22. This product uses the NVD API but is not endorsed or certified by the NVD.

**Technical analysis**

- [github.com — technical description](https://github.com/decolua/9router/blob/master/src/shared/utils/ssrfGuard.js)
- [github.com — technical description (route)](https://github.com/decolua/9router/blob/master/src/app/api/provider-nodes/validate/route.js)

**Third-party advisory**

- [vulncheck.com — third party advisory](https://www.vulncheck.com/advisories/9router-server-side-request-forgery-via-api-provider-nodes-validate-because-the-ipv4-mapped-ipv6-denylist-check-is-unreachable)

**Issue tracking and product pages**

- [github.com — issue tracking](https://github.com/decolua/9router/issues/3293)
- [github.com — issue tracking (3370)](https://github.com/decolua/9router/pull/3370)
- [github.com — product](https://github.com/decolua/9router)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-72860
Full detection coverage and IOCs for threats exploiting CVE-2026-72860 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
