Summary
CVE-2026-56266 is a critical Server-Side Request Forgery (SSRF) vulnerability in the Crawl4AI Docker API server, affecting all versions before 0.8.7. The flaw resides in the /crawl, /crawl/stream, /md, and /llm endpoints, which fetch arbitrary user-supplied URLs without adequate validation, and whose internal-address blocklist can be circumvented by encoding target addresses as IPv6-mapped IPv4 addresses. Unauthenticated remote attackers can exploit this to reach internal services and cloud metadata endpoints, with a CVSS v4.0 score of 9.2 (Critical).
Technical details
- Root cause: The
/crawl,/crawl/stream,/md, and/llmendpoints accept and fetch user-supplied URLs without sufficient destination validation. The internal-address blocklist fails to account for IPv6-mapped IPv4 representations (e.g.,::ffff:<internal-IP>), allowing the blocklist to be bypassed entirely. - Trigger conditions: An unauthenticated attacker submits a request to any of the affected endpoints with a crafted URL that encodes a blocked internal IPv4 address in IPv6-mapped form.
- Attack vector: Fully network-exploitable with no authentication required. The Crawl4AI Docker API server runs with JWT authentication disabled by default, meaning no credentials or session token are needed to interact with the affected endpoints.
- Impact: Successful exploitation allows the attacker to make the server issue arbitrary HTTP requests to internal network hosts and cloud metadata services (e.g., cloud instance metadata endpoints), potentially enabling exfiltration of cloud credentials and further lateral movement within the hosting environment.
Affected software
- Crawl4AI (PyPI package
crawl4ai) — all versions before 0.8.7
Severity
CVSS v3.1 Base Score: 8.6 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0 Base Score: 9.2 (CRITICAL)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade Crawl4AI to version 0.8.7 or later, which contains the vendor-issued fix for the IPv6-mapped IPv4 blocklist bypass in the direct crawl endpoints.
- Enable API authentication: Set the
CRAWL4AI_API_TOKENenvironment variable to require a bearer token on all API requests. - Replace the default JWT secret: Set a strong
SECRET_KEYvalue (minimum 32 characters) to replace the default hardcoded credential shipped with the project. - Network isolation: Restrict access to the Docker API server at the network perimeter — the service should not be directly reachable from the internet.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

