CVE-2026-46380
MEDIUM
6,7
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: low
Availability: none
Description
AI Translation Available
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue.
918
Server-Side Request Forgery (SSRF)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Web Based, AI/ML, Web Server
https://github.com/oscal-compass/compliance-trestle/commit/53de5e75332888ea54f5…
https://github.com/oscal-compass/compliance-trestle/commit/5c65c5926fe7ca908b9c…
https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-w7…
https://github.com/pypa/advisory-database/tree/main/vulns/compliance-trestle/PY…