PT-2026-38290 · Pypi · Dssrf
Published
2026-05-06
·
Updated
2026-05-12
·
CVE-2026-44232
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
dssrf versions prior to 1.3.0
Description
A flaw in the library allows attackers to bypass Server-Side Request Forgery (SSRF) protections by using various IPv6 address categories. This occurs because the
is url safe() function fails to properly block IPv6 addresses, including loopback, unique local addresses (ULA), link-local, and IPv4-mapped addresses, despite documentation claiming IPv6 was disabled.Recommendations
Update to version 1.3.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dssrf