PT-2026-41185 · Hmbown+1 · Codewhale+1

Jafarakhondali

·

Published

2026-05-14

·

Updated

2026-05-30

·

CVE-2026-45373

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CodeWhale versions prior to 0.8.26
Description Server-Side Request Forgery (SSRF) occurs when the application fails to properly validate IPv6 addresses provided directly in a URL, such as http://[::1]. While the system validates hostnames that resolve to private IPv6 addresses, direct IPv6 input bypasses these defenses, potentially allowing access to local restricted resources.
Recommendations Update to version 0.8.26.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45373
GHSA-88GH-2526-GFRR

Affected Products

Codewhale
Deepseek-Tui