PT-2026-38290 · Pypi · Dssrf

Published

2026-05-06

·

Updated

2026-05-12

·

CVE-2026-44232

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions dssrf versions prior to 1.3.0
Description A flaw in the library allows attackers to bypass Server-Side Request Forgery (SSRF) protections by using various IPv6 address categories. This occurs because the is url safe() function fails to properly block IPv6 addresses, including loopback, unique local addresses (ULA), link-local, and IPv4-mapped addresses, despite documentation claiming IPv6 was disabled.
Recommendations Update to version 1.3.0.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-44232
GHSA-8P33-Q827-GHJ5

Affected Products

Dssrf