CVE-2026-46380

⚪ Do wiadomości

Wykonanie ataku Server-Side Request Forgery w compliance-trestle umożliwia dostęp do wewnętrznych usług.

CVSS
6.7
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2026-08-14 17:18:14 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje