Description
safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIPv6(true), an attacker-controlled destination in one of these ranges is not recognized as non-public and can pass the SSRF destination check, potentially allowing access to resources hosted within the omitted ranges. IPv6 is disabled by default, and configurations that retain EnableIPv6(false) are not exposed to this bypass. This issue is fixed in version 0.2.4.
Published: 2026-09-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Internal network access via SSRF bypass
Action: Patch
AI Analysis

Impact

The safeurl library protects against SSRF by blocking requests to private network ranges. Prior to version 0.2.4, its privateNetwork list omitted the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 via EnableIPv6(true), a destination in any of these omitted ranges is incorrectly treated as public and passes the SSRF check, potentially allowing an attacker to access internal resources hosted in the omitted ranges. Although IPv6 is disabled by default, configurations that enable it remain vulnerable until upgraded to v0.2.4 or later.

Affected Systems

The vulnerability applies to the Doyensec safeurl library, versions earlier than 0.2.4. The fix was introduced in v0.2.4 and there are no known gaps in higher releases. Users running older releases that still enable IPv6 are affected.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, and the issue is not currently listed in CISA’s KEV catalog. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The flaw can be leveraged by any actor who can influence the destination URL in an application that has IPv6 enabled. Based on the description, it is inferred that the attack vector is application-level, requiring the attacker to trigger an HTTP request to a target, and the conditional check falls through when IPv6 is active, allowing internal network access.

Generated by OpenCVE AI on September 21, 2026 at 00:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade safeurl to version 0.2.4 or later
  • If upgrading is not immediately possible, disable IPv6 in the application configuration by setting EnableIPv6(false)
  • Confirm that the private network blocklist includes all relevant IPv6 ranges or customize the list to include missing ranges

Generated by OpenCVE AI on September 21, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xgch-x3mx-cm3c safeurl is Missing IPv6 CIDR Ranges in Blocklist
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Doyensec
Doyensec safeurl
Vendors & Products Doyensec
Doyensec safeurl

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIPv6(true), an attacker-controlled destination in one of these ranges is not recognized as non-public and can pass the SSRF destination check, potentially allowing access to resources hosted within the omitted ranges. IPv6 is disabled by default, and configurations that retain EnableIPv6(false) are not exposed to this bypass. This issue is fixed in version 0.2.4.
Title safeurl: Missing IPv6 CIDR Ranges in Blocklist
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Doyensec Safeurl
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:16:53.206Z

Reserved: 2026-06-15T15:30:40.318Z

Link: CVE-2026-54452

cve-icon Vulnrichment

Updated: 2026-09-16T15:16:47.867Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:47.330

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)