Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected.
This issue affects safeurl: from 0.1.0 onward.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected. This issue affects safeurl: from 0.1.0 onward. | |
| Title | SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts | |
| First Time appeared |
Slab
Slab safeurl |
|
| Weaknesses | CWE-636 CWE-918 |
|
| CPEs | cpe:2.3:a:slab:safeurl:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Slab
Slab safeurl |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-09-15T15:39:37.321Z
Reserved: 2026-08-30T00:00:01.985Z
Link: CVE-2026-77866
No data.
Status : Received
Published: 2026-09-15T16:17:24.117
Modified: 2026-09-15T16:17:24.117
Link: CVE-2026-77866
No data.
OpenCVE Enrichment
No data.