CVE Explorer
CVE-2026-32133
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows authenticated users to make arbitrary HTTP requests from the server to internal networks and cloud metadata endpoints. The image parameter in OTP URL is not properly validated for internal / private IP addresses before making HTTP requests. While the previous fix added response validation to ensure only valid images are
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"2FAuth","vendor":"Bubka","versions":[{"status":"affected","version":"< 6.1.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:295316c330514080e5bec94a72d90b0cc18a3e9734824feb9def9974336a2515 · sha256:a75028ad15c9aa9b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.8,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:295316c330514080e5bec94a72d90b0cc18a3e9734824feb9def9974336a2515 · sha256:a75028ad15c9aa9b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:295316c330514080e5bec94a72d90b0cc18a3e9734824feb9def9974336a2515 · sha256:a75028ad15c9aa9b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/Bubka/2FAuth/security/advisories/GHSA-8qp3-x2mp-j6f8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Bubka/2FAuth/security/advisories/GHSA-8qp3-x2mp-j6f8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:295316c330514080e5bec94a72d90b0cc18a3e9734824feb9def9974336a2515 · sha256:a75028ad15c9aa9b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.