Impact
The safeurl library protects against SSRF by blocking requests to private network ranges. Prior to version 0.2.4, its privateNetwork list omitted the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 via EnableIPv6(true), a destination in any of these omitted ranges is incorrectly treated as public and passes the SSRF check, potentially allowing an attacker to access internal resources hosted in the omitted ranges. Although IPv6 is disabled by default, configurations that enable it remain vulnerable until upgraded to v0.2.4 or later.
Affected Systems
The vulnerability applies to the Doyensec safeurl library, versions earlier than 0.2.4. The fix was introduced in v0.2.4 and there are no known gaps in higher releases. Users running older releases that still enable IPv6 are affected.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the issue is not currently listed in CISA’s KEV catalog. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The flaw can be leveraged by any actor who can influence the destination URL in an application that has IPv6 enabled. Based on the description, it is inferred that the attack vector is application-level, requiring the attacker to trigger an HTTP request to a target, and the conditional check falls through when IPv6 is active, allowing internal network access.
OpenCVE Enrichment
Github GHSA