CVE-2026-85740

Source
https://cve.org/CVERecord?id=CVE-2026-85740
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-85740.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-85740
Aliases
Published
2026-09-22T16:20:11Z
Modified
2026-09-24T03:47:30Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
Details

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 address embedded in an IPv6 transition wrapper. A caller who can upload a Markdown or textpack document can supply an external image URL using NAT64 64:ff9b::/96 or an IPv4-compatible form that embeds a loopback, private, or cloud-metadata IPv4 address. On a deployment with compatible NAT64 or DNS64 routing, _download and _build_guarded_opener accept the wrapper and fetch the internal resource, whose body is then ingested. Current interpreter behavior already blocks some RFC 8215 and 6to4 forms, but the fixed guard handles all documented wrappers without becoming more permissive than the standard library. This issue is fixed in version 1.5.5.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85740.json"
}
References

Affected packages

Git / github.com/hkuds/lightrag

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/lightrag
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.5.5"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
temp
v1.*
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.1.10
v1.1.11
v1.1.12
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.1.8
v1.1.9
v1.2.1
v1.2.2
v1.2.3
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v1.3.0
v1.3.1
v1.3.10
v1.3.2
v1.3.3
v1.3.4
v1.3.6
v1.3.7
v1.3.8
v1.3.9
v1.4.0
v1.4.1
v1.4.10
v1.4.11
v1.4.11rc1
v1.4.11rc2
v1.4.12
v1.4.12rc1
v1.4.13
v1.4.13rc1
v1.4.14
v1.4.15
v1.4.16
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.7rc2
v1.4.8
v1.4.8.1
v1.4.8.2
v1.4.8rc1
v1.4.8rc3
v1.4.8rc4
v1.4.8rc5
v1.4.8rc8
v1.4.8rc9
v1.4.9
v1.4.9.1
v1.4.9.10
v1.4.9.11
v1.4.9.2
v1.4.9.3
v1.4.9.4
v1.4.9.4rc1
v1.4.9.5
v1.4.9.6
v1.4.9.7
v1.4.9.8
v1.4.9.9
v1.4.9rc1
v1.4.9rc2
v1.4.9rc3
v1.4.9rc4
v1.5.0
v1.5.0rc2
v1.5.0rc3
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5rc1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-85740.json"