A vulnerability has been found in flytohub flyto-core up to 2.26.6 and classified as critical. The affected element is an unknown function of the file src/core/verification_service.py of the component flyto-verification service. This manipulation of the argument callback_url causes server-side request forgery.

This vulnerability is tracked as CVE-2026-67426. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.