Description
Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block.

Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected.

This issue affects safeurl: from 0.1.0 onward.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: SSRF enabling access to blocked internal resources
Action: Immediate Patch
AI Analysis

Impact

A server‑side request forgery flaw in Slab safeurl allows an attacker who can control a validated URL to reach internal network destinations that the library is configured to block. Only IPv4 addresses are checked against reserved ranges and a blocklist; every other address is treated as unmatched. Consequently, a destination rejected in its IPv4 form can be accessed when rewritten as an IPv6 address, IPv6 entries in the blocklist never match, and a host name that resolves to no IPv4 address is accepted regardless of where it points. The attack can lead to the disclosure of internal services or, if those services are exploitable, lateral movement or remote code execution.

Affected Systems

The vulnerability affects the Slab safeurl library beginning with version 0.1.0 and rely on safeurl’s allowlist configuration are not affected because an unmatched address is rejected in that mode.

Risk and Exploitability

The severity is high, with a CVSS score of 9. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack does not require special privileges beyond being able to supply a URL that passes safeurl’s validation; thus it can be executed in any context where safeurl is used to proxy or process user‑supplied URLs. Given the high CVSS score and the ability to bypass blocklists, the risk is significant for deployments that expose safeurl to untrusted input.

Generated by OpenCVE AI on September 20, 2026 at 15:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade safeurl to the latest release that includes the patch (or apply the commit referenced in the advisory to correct the IPv6 and unresolvable host handling).
  • If an upgrade is not feasible, reconfigure, which is not impacted by this flaw.
  • Limit the use of safeurl to inputs that come from trusted sources only and monitor outbound requests for unexpected internal network destinations.

Generated by OpenCVE AI on September 20, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected. This issue affects safeurl: from 0.1.0 onward.
Title SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts
First Time appeared Slab
Slab safeurl
Weaknesses CWE-636
CWE-918
CPEs cpe:2.3:a:slab:safeurl:*:*:*:*:*:*:*:*
Vendors & Products Slab
Slab safeurl
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-21T18:44:55.257Z

Reserved: 2026-08-30T00:00:01.985Z

Link: CVE-2026-77866

cve-icon Vulnrichment

Updated: 2026-09-21T18:44:52.163Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:24.117

Modified: 2026-09-21T19:17:10.973

Link: CVE-2026-77866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')

  • CWE-918

    Server-Side Request Forgery (SSRF)