Impact
A server‑side request forgery flaw in Slab safeurl allows an attacker who can control a validated URL to reach internal network destinations that the library is configured to block. Only IPv4 addresses are checked against reserved ranges and a blocklist; every other address is treated as unmatched. Consequently, a destination rejected in its IPv4 form can be accessed when rewritten as an IPv6 address, IPv6 entries in the blocklist never match, and a host name that resolves to no IPv4 address is accepted regardless of where it points. The attack can lead to the disclosure of internal services or, if those services are exploitable, lateral movement or remote code execution.
Affected Systems
The vulnerability affects the Slab safeurl library beginning with version 0.1.0 and rely on safeurl’s allowlist configuration are not affected because an unmatched address is rejected in that mode.
Risk and Exploitability
The severity is high, with a CVSS score of 9. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack does not require special privileges beyond being able to supply a URL that passes safeurl’s validation; thus it can be executed in any context where safeurl is used to proxy or process user‑supplied URLs. Given the high CVSS score and the ability to bypass blocklists, the risk is significant for deployments that expose safeurl to untrusted input.
OpenCVE Enrichment