Threat Advisory

Cloud Metadata Validator Bypassed by IPv4-mapped IPv6 Addresses

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52776, affects compliance-trestle versions 4.0.3 and earlier. The flaw exists in the URLSecurityValidator, whose incomplete network validation can be bypassed using IPv4-mapped IPv6 addresses and the 0.0.0.0 address. An attacker who can influence an OSCAL artifact processed by compliance-trestle could bypass SSRF protections and force the application to access cloud metadata services, loopback interfaces, or internal RFC 1918 networks.

• CVE-2026-52776 – An SSRF allowlist bypass allows malicious OSCAL profiles to evade URL validation using alternative IP representations, potentially enabling access to internal services, cloud metadata endpoints, and other restricted network resources.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52776, affects compliance-trestle versions 4.0.3 and earlier. The flaw exists in the URLSecurityValidator, whose incomplete network validation can be bypassed using IPv4-mapped IPv6 addresses and the 0.0.0.0 address. An attacker who can influence an OSCAL artifact processed by compliance-trestle could bypass SSRF protections and force the application to access cloud metadata services, loopback interfaces, or internal RFC 1918 networks.

• CVE-2026-52776 – An SSRF allowlist bypass allows malicious OSCAL profiles to evade URL validation using alternative IP representations, potentially enabling access to internal services, cloud metadata endpoints, and other restricted network resources.[emaillocker id="1283"]

RECOMMENDATION:

We recommend you to update compliance-trestle to version 4.1.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu