PT-2026-66794 · Pypi · Dssrf
CVE-2026-54729
·
Published
2026-07-31
·
Updated
2026-07-31
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DSSRF versions prior to 1.0.5
Description
The
is url safe() function can incorrectly identify localhost as safe when the DNS resolver 1.1.1.1 returns NXDOMAIN. This occurs because dns.resolve4 yields no address and no dns.lookup fallback is triggered, which enables server-side request forgery (SSRF), a technique where an attacker induces a server to make requests to an unintended location.Recommendations
Update DSSRF to version 1.0.5.
As a temporary workaround, consider restricting the use of the
is url safe() function until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dssrf