[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#compliance-trestle

articleCRITICAL 9.5

compliance-trestle URLSecurityValidator SSRF Allowlist Bypass via IPv4-Mapped IPv6 and 0.0.0.0

A critical vulnerability (CVE-2026-52776) was discovered in compliance-trestle, a Python package used for compliance and security. The vulnerability allows for an SSRF (Server-Side Request Forgery) allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0, potentially leading to unauthorized access to cloud-metadata services, loopback administrative interfaces, or RFC 1918 internal networks.

Aug 13, 20261 source