PT-2026-66794 · Pypi · Dssrf

CVE-2026-54729

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DSSRF versions prior to 1.0.5
Description The is url safe() function can incorrectly identify localhost as safe when the DNS resolver 1.1.1.1 returns NXDOMAIN. This occurs because dns.resolve4 yields no address and no dns.lookup fallback is triggered, which enables server-side request forgery (SSRF), a technique where an attacker induces a server to make requests to an unintended location.
Recommendations Update DSSRF to version 1.0.5. As a temporary workaround, consider restricting the use of the is url safe() function until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54729
GHSA-5846-7QM3-R52J

Affected Products

Dssrf