Description
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
Published: 2026-09-30
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery via IPv4‑mapped IPv6 bypass
Action: Patch immediately
AI Analysis

Impact

A Moodle flaw allows an authenticated remote user to supply an IPv4‑mapped IPv6 address in a URL meant for the internal downloader. Because the downloader’s host‑blocking logic misinterprets such addresses, the server can be coerced into making requests to destinations that are normally blocked. This bypass produces a Server‑Side Request Forgery that can reach internal or restricted resources, exposing confidential data or permitting further lateral movement.

Affected Systems

All Moodle installations that use the URL downloader feature are potentially vulnerable, regardless of the version, since no version‑specific mitigation is listed. Administrators should confirm whether their instance incorporates the affected code base and review the URL downloader configuration.

Risk and Exploitability

The CVSS score of 4.3 rates this as a low‑severity flaw, but the requirement of authenticated access means that access to a site with user credentials is sufficient for exploitation. Exploitability is therefore limited to situations where an attacker can log in to the Moodle instance. No EPSS score is provided, and the vulnerability is not in the CISA KEV list, indicating that it is not known to be actively exploited at scale.

Generated by OpenCVE AI on September 30, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Moodle to the latest version that contains the fix for this issue
  • Restrict the URL downloader to disallow IPv4‑mapped IPv6 addresses or apply a whitelist of approved hosts
  • Disable external URL downloads unless explicitly required and monitor access logs for anomalous requests

Generated by OpenCVE AI on September 30, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
Title Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T08:35:59.663Z

Reserved: 2026-09-29T14:03:38.493Z

Link: CVE-2026-102577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:14.660

Modified: 2026-09-30T09:17:14.660

Link: CVE-2026-102577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)