Impact
The vulnerability is a Time‑of‑check Time‑of‑use race condition in Slab safeurl, where the library returns only a verdict for a hostname resolution without binding that resolved address to the actual HTTP request. An attacker who can provide DNS responses for a given hostname can first return an IP address that passes validation. When the request is subsequently sent, the library performs another DNS lookup, and the attacker can return a different, blocked address that is actually used for the connection. This allows the attacker to reach internal destinations that the validator was intended to forbid, resulting in a critical compromise of internal network confidentiality and integrity.
Affected Systems
This issue affects the Slab safeurl library, versions 0.1.0 and later. Any Elixir application that relies on safeurl for outbound HTTP request validation is vulnerable until the library is updated to a fixed version or the application implements its own address binding logic.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity vulnerability. EPSS score of < 1% suggests a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the attack is target only needs to supply a name that the application already resolves. Consequently, the risk of exploitation in environments that allow arbitrary DNS configuration remains high. Could enable attackers to tunnel into internal resources that should be unreachable from external networks.
OpenCVE Enrichment