Description
Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected.

Validation returns a verdict and not the address it approved, so the HTTP clients the library ships receive the original hostname and resolve it a second time when the request is made. An attacker who controls the authoritative DNS for a name can answer the first lookup with a permitted address and the second with a blocked one, and the request then reaches a destination validation never approved. The same window opens without an attacker whenever a name legitimately resolves to different addresses across lookups, such as short record lifetimes or rotation between several addresses.

This issue affects safeurl: from 0.1.0 onward.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized internal network access via DNS rebinding
Action: Apply patch
AI Analysis

Impact

The vulnerability is a Time‑of‑check Time‑of‑use race condition in Slab safeurl, where the library returns only a verdict for a hostname resolution without binding that resolved address to the actual HTTP request. An attacker who can provide DNS responses for a given hostname can first return an IP address that passes validation. When the request is subsequently sent, the library performs another DNS lookup, and the attacker can return a different, blocked address that is actually used for the connection. This allows the attacker to reach internal destinations that the validator was intended to forbid, resulting in a critical compromise of internal network confidentiality and integrity.

Affected Systems

This issue affects the Slab safeurl library, versions 0.1.0 and later. Any Elixir application that relies on safeurl for outbound HTTP request validation is vulnerable until the library is updated to a fixed version or the application implements its own address binding logic.

Risk and Exploitability

The CVSS score of 9 indicates a high‑severity vulnerability. EPSS score of < 1% suggests a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the attack is target only needs to supply a name that the application already resolves. Consequently, the risk of exploitation in environments that allow arbitrary DNS configuration remains high. Could enable attackers to tunnel into internal resources that should be unreachable from external networks.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest safeurl release that includes the published fix (or backport the commit referenced in the advisory).
  • Modify the application to perform the hostname‑to‑IP validation and reuse the same IP address for the outgoing HTTP request, preventing a second DNS lookup.
  • If immediate upgrading is not possible, restrict DNS responses to trusted authoritative servers or block untrusted internal IP ranges at the network firewall or DNS server level.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address it approved, so the HTTP clients the library ships receive the original hostname and resolve it a second time when the request is made. An attacker who controls the authoritative DNS for a name can answer the first lookup with a permitted address and the second with a blocked one, and the request then reaches a destination validation never approved. The same window opens without an attacker whenever a name legitimately resolves to different addresses across lookups, such as short record lifetimes or rotation between several addresses. This issue affects safeurl: from 0.1.0 onward.
Title safeurl validated address is not bound to the request, allowing DNS rebinding
First Time appeared Slab
Slab safeurl
Weaknesses CWE-367
CPEs cpe:2.3:a:slab:safeurl:*:*:*:*:*:*:*:*
Vendors & Products Slab
Slab safeurl
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-21T18:44:16.787Z

Reserved: 2026-08-24T15:45:02.127Z

Link: CVE-2026-77972

cve-icon Vulnrichment

Updated: 2026-09-21T18:44:10.626Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:24.290

Modified: 2026-09-21T19:17:11.153

Link: CVE-2026-77972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition