A high-severity Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52776, affects compliance-trestle versions 4.0.3 and earlier. The flaw exists in the URLSecurityValidator, whose incomplete network validation can be bypassed using IPv4-mapped IPv6 addresses and the 0.0.0.0 address. An attacker who can influence an OSCAL artifact processed by compliance-trestle could bypass SSRF protections and force the application to access cloud metadata services, loopback interfaces, or internal RFC 1918 networks.
• CVE-2026-52776 – An SSRF allowlist bypass allows malicious OSCAL profiles to evade URL validation using alternative IP representations, potentially enabling access to internal services, cloud metadata endpoints, and other restricted network resources.[/subscribe_to_unlock_form]
A high-severity Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52776, affects compliance-trestle versions 4.0.3 and earlier. The flaw exists in the URLSecurityValidator, whose incomplete network validation can be bypassed using IPv4-mapped IPv6 addresses and the 0.0.0.0 address. An attacker who can influence an OSCAL artifact processed by compliance-trestle could bypass SSRF protections and force the application to access cloud metadata services, loopback interfaces, or internal RFC 1918 networks.
• CVE-2026-52776 – An SSRF allowlist bypass allows malicious OSCAL profiles to evade URL validation using alternative IP representations, potentially enabling access to internal services, cloud metadata endpoints, and other restricted network resources.[emaillocker id="1283"]
We recommend you to update compliance-trestle to version 4.1.0.
The following reports contain further technical details:
[/emaillocker]